A vulnerability classified as problematic has been found in PHP up to 8.0.29. This affects an unknown part. The manipulation leads to xml external entity reference.
This vulnerability is uniquely identified as CVE-2023-3823. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in PHP up to 8.0.29. This vulnerability affects the function phar_dir_read of the component PHAR Handler. The manipulation leads to buffer overflow.
This vulnerability was named CVE-2023-3824. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in PHP up to 8.0.27/8.1.15/8.2.2. It has been rated as problematic. This issue affects the function password_verify of the component Blowfish Hash Handler. The manipulation leads to incorrect implementation of authentication algorithm.
The identification of this vulnerability is CVE-2023-0567. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in PHP up to 8.0.28/8.1.19/8.2.6. Affected is the function php_random_bytes_throw of the file ext/soap/php_http.c of the component SOAP HTTP Digest Authentication. The manipulation leads to small space of random values.
This vulnerability is traded as CVE-2023-3247. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Oracle Secure Backup 18.1.0.1.0/18.1.0.2.0. It has been classified as critical. This affects an unknown part of the component Secure Backup. The manipulation leads to incorrect calculation of buffer size.
This vulnerability is uniquely identified as CVE-2023-0568. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability has been found in Oracle Communications Unified Assurance up to 6.0.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Core. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2023-3247. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in Linux Kernel up to 5.10.227/5.15.168/6.1.113/6.6.57/6.11.4. It has been classified as problematic. Affected is the function vmapp_count of the component gic-v4. The manipulation leads to Privilege Escalation.
This vulnerability is traded as CVE-2024-50192. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 5.10.227/5.15.168/6.1.113/6.6.57/6.11.4. It has been rated as critical. Affected by this issue is the function rq_qos_wake_function of the component blk-rq-qos. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2024-50082. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in Linux Kernel up to 6.6.8. This vulnerability affects the function bt_sock_recvmsg of the file net/bluetooth/af_bluetooth.c. The manipulation leads to use after free.
This vulnerability was named CVE-2023-51779. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability has been found in Linux Kernel up to 6.10.6 and classified as critical. This vulnerability affects the function iommu_report_device_fault. The manipulation leads to denial of service.
This vulnerability was named CVE-2024-44994. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in PHP up to 8.1.27/8.2.17/8.3.4. This vulnerability affects unknown code of the component Cookie Handler. The manipulation leads to improper input validation.
This vulnerability was named CVE-2024-2756. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in matrix-org matrix-js-sdk up to 34.11.0 on JavaScript and classified as critical. This issue affects some unknown processing of the component MXC URI Handler. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2024-50336. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Apple macOS up to 13.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Perl. The manipulation leads to state issue.
This vulnerability is known as CVE-2023-32395. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A financial firm registered in Canada has emerged as the payment processor for dozens of Russian cryptocurrency exchanges and websites hawking cybercrime services aimed at Russian-speaking customers, new research finds. Meanwhile, an investigation into the Vancouver street address used by this company shows it is home to dozens of foreign currency dealers, money transfer businesses, and cryptocurrency exchanges -- none of which are physically located there.