Show filters
3,617 Total Results
Displaying 311-320 of 3,617
Sort by:
Attacker Value
Unknown

CVE-2023-41358

Disclosure Date: August 29, 2023 (last updated February 25, 2025)
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
Attacker Value
Unknown

CVE-2020-24165

Disclosure Date: August 28, 2023 (last updated May 15, 2024)
An issue was discovered in TCG Accelerator in QEMU 4.2.0, allows local attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS). Note: This is disputed as a bug and not a valid security issue by multiple third parties.
Attacker Value
Unknown

CVE-2023-41080

Disclosure Date: August 25, 2023 (last updated February 25, 2025)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. The vulnerability is limited to the ROOT (default) web application.
Attacker Value
Unknown

CVE-2023-40577

Disclosure Date: August 25, 2023 (last updated February 25, 2025)
Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.
Attacker Value
Unknown

CVE-2023-4431

Disclosure Date: August 23, 2023 (last updated February 25, 2025)
Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Attacker Value
Unknown

CVE-2022-48566

Disclosure Date: August 22, 2023 (last updated February 25, 2025)
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.
Attacker Value
Unknown

CVE-2022-48565

Disclosure Date: August 22, 2023 (last updated February 25, 2025)
An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.
Attacker Value
Unknown

CVE-2022-48560

Disclosure Date: August 22, 2023 (last updated February 25, 2025)
A use-after-free exists in Python through 3.9 via heappushpop in heapq.
Attacker Value
Unknown

CVE-2022-44730

Disclosure Date: August 22, 2023 (last updated February 25, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. A malicious SVG can probe user profile / data and send it directly as parameter to a URL.
Attacker Value
Unknown

CVE-2022-44729

Disclosure Date: August 22, 2023 (last updated February 25, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.