|
111
|
5.3
-
|
MEDIUM
Network
|
sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowi…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2023-51765
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 17:38
2023-12-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
112
|
5.3
-
|
MEDIUM
Network
|
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in re…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2023-51764
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 17:38
2023-12-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
113
|
7.0
-
|
HIGH
Local
|
A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line d…
|
CWE-362
Race Condition
|
CVE-2023-6546
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 17:44
2023-12-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
114
|
5.3
-
|
MEDIUM
Network
|
A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked,…
|
CWE-252
Unchecked Return Value
|
CVE-2023-6918
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 17:44
2023-12-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
115
|
5.9
-
|
MEDIUM
Network
|
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2023-48795
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 17:32
2023-12-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
116
|
5.4
-
|
MEDIUM
Network
|
A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (X…
|
CWE-79
Cross-site Scripting
|
CVE-2023-6710
|
cpe:2.3:o:redhat:enterprise_linux:9.0:*
|
|
|
|
|
2024-11-21 17:44
2023-12-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
117
|
5.5
-
|
MEDIUM
Local
|
A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c in the Digital Phase Locked Loop (DPLL) subsystem in the Linux kernel. This issue could…
|
CWE-476
NULL Pointer Dereference
|
CVE-2023-6679
|
cpe:2.3:o:redhat:enterprise_linux:9.0:*
|
|
|
|
|
2024-11-21 17:44
2023-12-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
118
|
4.3
-
|
MEDIUM
Network
|
A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handli…
|
NVD-CWE-noinfo
|
CVE-2023-5868
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 17:42
2023-12-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
119
|
4.4
-
|
MEDIUM
Network
|
A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Succe…
|
NVD-CWE-noinfo
|
CVE-2023-5870
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 17:42
2023-12-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
120
|
8.8
-
|
HIGH
Network
|
A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an inte…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2023-5869
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 17:42
2023-12-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|