VulnSea

Tagged “vex”

CVEs tagged vex, newest first.

3567 CVEsRSS

CVE-2021-47028High· 7.1⚖ disputed
2y ago

In the Linux kernel, the following vulnerability has been resolved: mt76: mt7915: fix txrate reporting Properly check rate_info to fix unexpected reporting. [ 1215.161863] Call trace: [ 1215.164307] cfg80211_calculate_bitrate+0x124/0…

In the Linux kernel, the following vulnerability has been resolved: mt76: mt7915: fix txrate reporting Properly check rate_info to fix unexpected reporting. [ 1215.161863] Call trace: [ 1215.164307] cfg80211_calculate_bitrate+0x124/0…

▾ Twilightlinux · linux_kernelEPSS 0.35%via NVD
CVE-2021-47014High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix wild memory access when clearing fragments while testing re-assembly/re-fragmentation using act_ct, it's possible to observe a crash like the fo…

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix wild memory access when clearing fragments while testing re-assembly/re-fragmentation using act_ct, it's possible to observe a crash like the fo…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2023-52461High· 7.8⚖ disputed
2y ago

In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix bounds limiting when given a malformed entity If we're given a malformed entity in drm_sched_entity_init()--shouldn't happen, but we verify--with out-of…

In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix bounds limiting when given a malformed entity If we're given a malformed entity in drm_sched_entity_init()--shouldn't happen, but we verify--with out-of…

▾ Twilightlinux · linux_kernelEPSS 0.46%via NVD
CVE-2023-52454High· 7.5
2y ago

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix a kernel panic when host sends an invalid H2C PDU length If the host sends an H2CData command with an invalid DATAL, the kernel may crash in nvmet_tcp_b…

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix a kernel panic when host sends an invalid H2C PDU length If the host sends an H2CData command with an invalid DATAL, the kernel may crash in nvmet_tcp_b…

▾ Twilightlinux · linux_kernelEPSS 0.68%via NVD
CVE-2023-52447High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: bpf: Defer the free of inner map when necessary When updating or deleting an inner map in map array or map htab, the map may still be accessed by non-sleepable program…

In the Linux kernel, the following vulnerability has been resolved: bpf: Defer the free of inner map when necessary When updating or deleting an inner map in map array or map htab, the map may still be accessed by non-sleepable program…

▾ Twilightlinux · linux_kernelEPSS 0.25%via NVD
CVE-2023-6291High· 7.1
2y ago

A flaw was found in the redirect_uri validation logic in Keycloak

A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to …

▾ Twilightredhat · keycloakEPSS 0.95%via NVD
CVE-2024-22195Medium· 5.4
2y ago

Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter

Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter

▾ Sunlitjinja2 · jinja2EPSS 0.89%via OSV
CVE-2023-52323Medium· 5.3
2y ago

PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption

PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption

▾ Sunlitpycryptodomex · pycryptodomexEPSS 0.62%via OSV
CVE-2023-6927Medium· 4.6
2y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to…

▾ Sunlitredhat · keycloakEPSS 1.1%via NVD
CVE-2023-6563High· 7.7
2y ago

An unconstrained memory consumption vulnerability was discovered in Keycloak

An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates …

▾ Twilightredhat · keycloakEPSS 1.2%via NVD
CVE-2023-6134Medium· 4.6
2y ago

A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token

A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-site scripting (X…

▾ Sunlitredhat · single_sign-onEPSS 1.3%via NVD
CVE-2023-6710Medium· 5.4PoC
2y ago

A flaw was found in the mod_proxy_cluster in the Apache server

A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the URL to trigger the stored cross-site scripting (XSS) vulnerability. By adding a script …

▾ Twilightmodcluster · mod_proxy_clusterEPSS 2.2%via NVD
CVE-2023-4061Medium· 6.5
2y ago

A flaw was found in wildfly-core

A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and ob…

▾ Sunlitredhat · jboss_enterprise_application_platformEPSS 0.83%via NVD
CVE-2023-45853Critical· 9.8⚖ disputed
2y ago

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pymini…

▾ Midnightzlib · zlibEPSS 3.2%via NVD
CVE-2023-4822Medium· 6.7
2y ago

grafana: incorrect assessment of permissions across organizations (CVE-2023-4822)

A flaw was found in the Grafana enterprise package. Grafana is incorrectly assessing permissions to update global roles and role assignments, therefore, users with administrator permissions in one organization can change global role permis…

▾ SunlitRed Hat · Red Hat Ceph Storage 7.1 ToolsEPSS 1.1%via CSAF
CVE-2023-5535High· 7.8⚖ disputed
2y ago

Use After Free in GitHub repository vim/vim prior to v9.0.2010.

Use After Free in GitHub repository vim/vim prior to v9.0.2010.

▾ Twilightneovim · neovimEPSS 0.51%via NVD
CVE-2023-4611High· 7.0
3y ago

A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel

A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is caused by a race between mbind() and VMA-locked page fault, and may allow a local attacker to crash the system or lea…

▾ Twilightlinux · linux_kernelEPSS 0.27%via NVD
CVE-2023-2426Medium· 5.3
3y ago

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.

▾ Sunlitneovim · neovimEPSS 0.41%via NVD
CVE-2023-28840High· 7.5
3y ago

Moby is an open source container framework developed by Docker Inc

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as m…

▾ Twilightmobyproject · mobyEPSS 2.6%via NVD
CVE-2023-28841Medium· 6.8
3y ago

Moby is an open source container framework developed by Docker Inc

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as m…

▾ Sunlitmobyproject · mobyEPSS 0.69%via NVD
CVE-2023-28842Medium· 6.8
3y ago

moby: Encrypted overlay network with a single endpoint is unauthenticated (CVE-2023-28842)

A vulnerability was found in Moby due to an unprotected alternate channel within encrypted overlay networks, which could allow a remote attacker to bypass security restrictions. By sending a specially crafted request, an attacker could inj…

▾ SunlitRed Hat · multicluster engine for Kubernetes 2.4 for RHEL 8EPSS 1.4%via CSAF
CVE-2023-1380High· 7.1
3y ago

A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel

A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buf…

▾ Twilightredhat · enterprise_linuxEPSS 17%via NVD
CVE-2023-27534Low· 3.7PoC⚖ disputed
3y ago

curl: SFTP path ~ resolving discrepancy (CVE-2023-27534)

A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicat…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 9)EPSS 2.2%via CSAF
CVE-2023-27522High· 7.5
3y ago

httpd: mod_proxy_uwsgi HTTP response splitting (CVE-2023-27522)

An HTTP Response Smuggling vulnerability was found in the Apache HTTP Server via mod_proxy_uwsgi. This security issue occurs when special characters in the origin response header can truncate or split the response forwarded to the client.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream EUS (v.8.6)EPSS 2.1%via CSAF
CVE-2023-0594High· 7.3
3y ago

grafana: cross site scripting (CVE-2023-0594)

A flaw was found in the grafana package. This flaw allows a malicious user with the ability to introduce trace data to provide a JavaScript that changes the password for the user viewing the trace view (this could be an admin) to a known p…

▾ TwilightRed Hat · Red Hat Ceph Storage 5.3 ToolsEPSS 9.2%via CSAF
CVE-2023-25153Medium· 5.5
3y ago

containerd: OCI image importer memory exhaustion (CVE-2023-25153)

A flaw was found in containerd. When importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file, where a limit was not applied could cause a denial of service.

▾ SunlitRed Hat · Red Hat Ceph Storage 9.0 ToolsEPSS 0.36%via CSAF
CVE-2023-0286High· 7.4
3y ago

openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286)

A type confusion vulnerability was found in OpenSSL when OpenSSL X.400 addresses processing inside an X.509 GeneralName. When CRL checking is enabled (for example, the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability ma…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 60%via CSAF
CVE-2022-39324Medium· 6.7
3y ago

grafana: Spoofing of the originalUrl parameter of snapshots (CVE-2022-39324)

A flaw was found in the grafana package. While creating a snapshot, an attacker may manipulate a hidden HTTP parameter to inject a malicious URL in the "Open original dashboard" button.

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.83%via CSAF
CVE-2023-0433High· 7.8
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.

▾ Twilightneovim · neovimEPSS 0.52%via NVD
CVE-2023-0288High· 7.8
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.

▾ Twilightneovim · neovimEPSS 0.48%via NVD
CVEs tagged “vex” — page 118 · VulnSea