|
281
|
5.5
-
|
MEDIUM
Local
|
A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file …
|
CWE-20
Improper Input Validation
|
CVE-2023-1289
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 16:38
2023-03-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282
|
8.6
-
|
HIGH
Network
|
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a…
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2022-4904
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 16:36
2023-03-7
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283
|
8.8
-
|
HIGH
Network
|
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple m…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-8720
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 13:50
2023-03-7
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284
|
5.5
-
|
MEDIUM
Local
|
A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VGA card system resource overload, causing a fail in the intel_gvt_dma_map_guest_page function. This …
|
CWE-415
Double Free
|
CVE-2022-3707
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2025-03-8 01:15
2023-03-7
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285
|
7.8
-
|
HIGH
Local
|
A use-after-free flaw was found in the Linux kernel’s SGI GRU driver in the way the first gru_file_unlocked_ioctl function is called by the user, where a fail pass occurs in the gru_check_chiplet_ass…
|
CWE-416
Use After Free
|
CVE-2022-3424
|
cpe:2.3:o:redhat:enterprise_linux:9.0:*
|
|
|
|
|
2025-03-7 06:15
2023-03-7
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286
|
7.0
-
|
HIGH
Local
|
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with cu…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2023-27561
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 16:53
2023-03-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287
|
3.7
-
|
LOW
Network
|
In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to…
|
NVD-CWE-noinfo
|
CVE-2022-41862
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2025-03-8 01:15
2023-03-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288
|
5.5
-
|
MEDIUM
Local
|
In nf_tables_updtable, if nf_tables_table_enable returns an error, nft_trans_destroy is called to free the transaction object. nft_trans_destroy() calls list_del(), but the transaction was never plac…
|
CWE-476
NULL Pointer Dereference
|
CVE-2023-1095
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 16:38
2023-03-1
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289
|
7.4
-
|
HIGH
Network
|
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a netwo…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2023-0361
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 16:37
2023-02-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290
|
5.5
-
|
MEDIUM
Local
|
A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories …
|
CWE-22
Path Traversal
|
CVE-2022-3560
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 16:19
2023-02-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|