Where
AND
AND
-Infinity
0
Severity
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.

1 / 2
Source: NVD
First published (updated )
Severity
6.3
EPSS
0.05%
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.

First published (updated )
Severity
6.5
EPSS
0.08%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Last updated 24 July 2024

1 / 6
Source: Ubuntu
First published (updated )
Severity
6.5
EPSS
0.06%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EncryptingOutputStream was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local disk which may have implications for private browsing mode.

External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-54/#CVE-2023-6865

1 / 6
Source: Red Hat
First published (updated )
Severity
5.3
EPSS
0.11%
Race Condition
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

Last updated 24 July 2024

1 / 7
Source: Ubuntu
First published (updated )
Severity
4.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Last updated 24 July 2024

1 / 4
Source: Ubuntu
First published (updated )
Severity
4.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Last updated 24 July 2024

1 / 4
Source: Ubuntu
First published (updated )
Severity
6.1
EPSS
0.05%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Last updated 24 July 2024

1 / 4
Source: Ubuntu
First published (updated )
Severity
6.5
EPSS
0.07%
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash.

1 / 4
Source: Mozilla
First published (updated )
Severity
6.5
EPSS
0.08%
Path Traversal
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites.

1 / 4
Source: Mozilla
First published (updated )
Severity
6.5
EPSS
0.07%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on the canvas element. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

1 / 4
Source: Ubuntu
First published (updated )
Severity
5.4
EPSS
0.09%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear.

1 / 4
Source: Mozilla
First published (updated )
Severity
6.1
XSS
AC:L/AV:N/A:N/C:L/I:L/PR:N/S:C/UI:R

Last updated 24 July 2024

1 / 2
Source: Ubuntu
First published (updated )
Severity
6.5
Buffer Overflow, Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Automation. The issue was addressed with improved checks.

1 / 37
Source: Apple
First published (updated )
Severity
6.1
EPSS
0.15%
XSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Chromium: CVE-2023-5480 Inappropriate implementation in Payments

1 / 3
Source: Microsoft
First published (updated )
Severity
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision existence is leaked due to incorrect permissions being checked. This reveals that a given revision ID belonged to the given page title, and its timestamp, both of which are not supposed to be public information.

First published (updated )
Severity
6.5
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash.

1 / 4
Source: Mozilla
First published (updated )
Severity
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

A compromised content process could have provided malicious data in a PathRecording resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process.

External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-42/#CVE-2023-5169

1 / 4
Source: Red Hat
First published (updated )
Severity
6.3
EPSS
0.35%
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Chromium: CVE-2023-5473 Use after free in Cast

1 / 3
Source: Microsoft
First published (updated )
Severity
4.3
EPSS
0.20%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Chromium: CVE-2023-5859 Incorrect security UI in Picture In Picture

1 / 3
Source: Microsoft
First published (updated )
Severity
4.3
EPSS
0.13%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Chromium: CVE-2023-6511 Inappropriate implementation in Autofill

1 / 3
Source: Microsoft
First published (updated )
Severity
6.5
EPSS
0.03%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Chromium: CVE-2023-5475 Inappropriate implementation in DevTools

1 / 3
Source: Microsoft
First published (updated )
Severity
5.5
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

A memory leak flaw was found in nftsetcatchallflush in net/netfilter/nftablesapi.c in the Linux Kernel. This issue may allow a local attacker to cause a double-deactivations of catchall elements, which results in a memory leak.

1 / 4
First published (updated )
Severity
4.3
EPSS
0.14%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Chromium: CVE-2023-5851 Inappropriate implementation in Downloads

1 / 3
Source: Microsoft
First published (updated )
Severity
4.3
EPSS
0.02%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Chromium: CVE-2023-5477 Inappropriate implementation in Installer

1 / 3
Source: Microsoft
First published (updated )
Severity
6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.

1 / 2
First published (updated )
Severity
6.5
EPSS
0.03%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Chromium: CVE-2023-5479 Inappropriate implementation in Extensions API

1 / 3
Source: Microsoft
First published (updated )
Severity
5.5
Divide by Zero
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality.

1 / 3
Source: Launchpad
First published (updated )
Severity
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Last updated 24 July 2024

1 / 4
Source: Ubuntu
First published (updated )
Severity
5.9
Use After Free, Race Condition
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Last updated 24 July 2024

1 / 4
Source: Ubuntu
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203