Show filters
708 Total Results
Displaying 61-70 of 708
Sort by:
Attacker Value
Unknown

CVE-2023-1813

Disclosure Date: April 04, 2023 (last updated October 25, 2023)
Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.49 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Attacker Value
Unknown

CVE-2023-1812

Disclosure Date: April 04, 2023 (last updated October 25, 2023)
Out of bounds memory access in DOM Bindings in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Attacker Value
Unknown

CVE-2023-1811

Disclosure Date: April 04, 2023 (last updated October 21, 2023)
Use after free in Frames in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Attacker Value
Unknown

CVE-2023-1810

Disclosure Date: April 04, 2023 (last updated October 21, 2023)
Heap buffer overflow in Visuals in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Attacker Value
Unknown

CVE-2023-26916

Disclosure Date: April 03, 2023 (last updated October 08, 2023)
libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at lys_parse_mem.c.
Attacker Value
Unknown

CVE-2023-1611

Disclosure Date: April 03, 2023 (last updated October 08, 2023)
A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux Kernel.This flaw allows an attacker to crash the system and possibly cause a kernel information lea
Attacker Value
Unknown

CVE-2022-36440

Disclosure Date: April 03, 2023 (last updated February 01, 2024)
A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.
Attacker Value
Unknown

CVE-2023-28756

Disclosure Date: March 31, 2023 (last updated October 08, 2023)
A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.
Attacker Value
Unknown

CVE-2023-28755

Disclosure Date: March 31, 2023 (last updated October 08, 2023)
A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.
Attacker Value
Unknown

CVE-2023-1393

Disclosure Date: March 30, 2023 (last updated October 08, 2023)
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.