Vulnerabilities
Vulnerable Software
Debian:  Security Vulnerabilities
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-47318.
CVSS Score
8.0
EPSS Score
0.018
Published
2023-01-17
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-46648.
CVSS Score
8.0
EPSS Score
0.007
Published
2023-01-17
The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.
CVSS Score
6.5
EPSS Score
0.002
Published
2023-01-14
In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition.
CVSS Score
7.8
EPSS Score
0.0
Published
2023-01-13
A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c file. The flaw occurs because the function lacks check of the return value of avformat_new_stream() and triggers the null pointer dereference error, causing an application to crash.
CVSS Score
5.3
EPSS Score
0.001
Published
2023-01-12
atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results).
CVSS Score
5.5
EPSS Score
0.0
Published
2023-01-12
cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results).
CVSS Score
5.5
EPSS Score
0.001
Published
2023-01-12
An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.
CVSS Score
9.8
EPSS Score
0.005
Published
2023-01-10
An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
CVSS Score
9.8
EPSS Score
0.004
Published
2023-01-10
A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) advertising eIBRS support to L1. An attacker at L2 with code execution can execute code on an indirect branch on the host machine. We recommend upgrading to Kernel 6.2 or past commit 2e7eab81425a
CVSS Score
5.8
EPSS Score
0.0
Published
2023-01-09


Contact Us

Shodan ® - All rights reserved