Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In February 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 before 15.6.7, all versions starting from 15.7 before 15.7.6, all versions starting from 15.8 before 15.8.1. It was possible to trigger a DoS attack by uploading a malicious Helm chart.
CVSS Score
4.3
EPSS Score
0.006
Published
2023-02-13
LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3488, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit afaabc3e.
CVSS Score
6.8
EPSS Score
0.0
Published
2023-02-13
LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3592, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit afaabc3e.
CVSS Score
6.8
EPSS Score
0.0
Published
2023-02-13
LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6921, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit afaabc3e.
CVSS Score
6.8
EPSS Score
0.0
Published
2023-02-13
A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8 before 15.8.1 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.
CVSS Score
6.5
EPSS Score
0.005
Published
2023-02-13
A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.
CVSS Score
9.8
EPSS Score
0.0
Published
2023-02-13
Buffer Over-read in GitHub repository gpac/gpac prior to v2.3.0-DEV.
CVSS Score
7.3
EPSS Score
0.001
Published
2023-02-13
Off-by-one Error in GitHub repository gpac/gpac prior to v2.3.0-DEV.
CVSS Score
7.1
EPSS Score
0.0
Published
2023-02-13
Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to v2.3.0-DEV.
CVSS Score
7.8
EPSS Score
0.0
Published
2023-02-13
A vulnerability was found in juju2143 WalrusIRC 0.0.2. It has been rated as problematic. This issue affects the function parseLinks of the file public/parser.js. The manipulation of the argument text leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 0.0.3 is able to address this issue. The patch is named 45fd885895ae13e8d9b3a71e89d59768914f60af. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-220751.
CVSS Score
3.5
EPSS Score
0.001
Published
2023-02-13


Contact Us

Shodan ® - All rights reserved