Show filters
9,045 Total Results
Displaying 281-290 of 9,045
Sort by:
Attacker Value
Unknown
CVE-2024-0567
Disclosure Date: January 16, 2024 (last updated February 26, 2025)
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.
0
Attacker Value
Unknown
CVE-2023-6040
Disclosure Date: January 12, 2024 (last updated February 26, 2025)
An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family); While creating a new netfilter table, lack of a safeguard against invalid nf_tables family (pf) values within `nf_tables_newtable` function enables an attacker to achieve out-of-bounds access.
0
Attacker Value
Unknown
CVE-2023-51782
Disclosure Date: January 11, 2024 (last updated February 26, 2025)
An issue was discovered in the Linux kernel before 6.6.8. rose_ioctl in net/rose/af_rose.c has a use-after-free because of a rose_accept race condition.
0
Attacker Value
Unknown
CVE-2023-51781
Disclosure Date: January 11, 2024 (last updated February 26, 2025)
An issue was discovered in the Linux kernel before 6.6.8. atalk_ioctl in net/appletalk/ddp.c has a use-after-free because of an atalk_recvmsg race condition.
0
Attacker Value
Unknown
CVE-2023-51780
Disclosure Date: January 11, 2024 (last updated February 26, 2025)
An issue was discovered in the Linux kernel before 6.6.8. do_vcc_ioctl in net/atm/ioctl.c has a use-after-free because of a vcc_recvmsg race condition.
0
Attacker Value
Unknown
CVE-2023-51766
Disclosure Date: December 24, 2023 (last updated February 25, 2025)
Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other popular e-mail servers do not.
0
Attacker Value
Unknown
CVE-2023-6931
Disclosure Date: December 19, 2023 (last updated February 25, 2025)
A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation.
A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group().
We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.
0
Attacker Value
Unknown
CVE-2023-6873
Disclosure Date: December 19, 2023 (last updated February 25, 2025)
Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 121.
0
Attacker Value
Unknown
CVE-2023-6867
Disclosure Date: December 19, 2023 (last updated February 25, 2025)
The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.
0
Attacker Value
Unknown
CVE-2023-6865
Disclosure Date: December 19, 2023 (last updated February 02, 2024)
`EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local disk which may have implications for private browsing mode. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.
0