2023 CVE Vulnerabilities
31,248 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-6870 | MEDIUM | 4.3 | 0.4% | Dec 19, 2023 | Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displaye... |
| CVE-2023-6869 | MEDIUM | 6.5 | 0.6% | Dec 19, 2023 | A `<dialog>` element could have been manipulated to paint content outside of a sandboxed iframe. This could allow unt... |
| CVE-2023-6868 | MEDIUM | 4.3 | 0.5% | Dec 19, 2023 | In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subs... |
| CVE-2023-6867 | MEDIUM | 6.1 | 0.7% | Dec 19, 2023 | The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking del... |
| CVE-2023-6866 | HIGH | 8.8 | 0.7% | Dec 19, 2023 | TypedArrays can be fallible and lacked proper exception handling. This could lead to abuse in other APIs which expect Ty... |
| CVE-2023-6865 | MEDIUM | 6.5 | 0.9% | Dec 19, 2023 | `EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be abused in order to wr... |
| CVE-2023-6864 | HIGH | 8.8 | 1.2% | Dec 19, 2023 | Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these bugs showed evidence ... |
| CVE-2023-6863 | HIGH | 8.8 | 1.0% | Dec 19, 2023 | The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that la... |
| CVE-2023-6862 | HIGH | 8.8 | 1.0% | Dec 19, 2023 | A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely during start-up. Thi... |
| CVE-2023-6861 | HIGH | 8.8 | 1.4% | Dec 19, 2023 | The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vu... |
| CVE-2023-6860 | MEDIUM | 6.5 | 1.0% | Dec 19, 2023 | The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to esca... |
| CVE-2023-6859 | HIGH | 8.8 | 1.1% | Dec 19, 2023 | A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox E... |
| CVE-2023-6858 | HIGH | 8.8 | 1.5% | Dec 19, 2023 | Firefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handling. This vulnerabili... |
| CVE-2023-6857 | MEDIUM | 5.3 | 0.7% | Dec 19, 2023 | When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary.... |
| CVE-2023-6856 | HIGH | 8.8 | 20.5% | Dec 19, 2023 | The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM... |
| CVE-2023-6135 | MEDIUM | 4.3 | 0.7% | Dec 19, 2023 | Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially all... |
| CVE-2023-50762 | MEDIUM | 4.3 | 0.6% | Dec 19, 2023 | When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown ... |
| CVE-2023-50761 | MEDIUM | 4.3 | 0.6% | Dec 19, 2023 | The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If... |
| CVE-2023-6730 | HIGH | 8.8 | 0.9% | Dec 19, 2023 | Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36. |
| CVE-2023-6945 | MEDIUM | 4.8 | 0.6% | Dec 19, 2023 | A vulnerability has been found in SourceCodester Online Student Management System 1.0 and classified as problematic. Aff... |
| CVE-2023-49736 | HIGH | 8.8 | 1.2% | Dec 19, 2023 | A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow fo... |
| CVE-2023-49734 | MEDIUM | 6.5 | 0.9% | Dec 19, 2023 | An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically be... |
| CVE-2023-49489 | MEDIUM | 6.1 | 0.7% | Dec 19, 2023 | Reflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive in... |
| CVE-2023-49006 | MEDIUM | 6.5 | 0.5% | Dec 19, 2023 | Cross Site Request Forgery (CSRF) vulnerability in Phpsysinfo version 3.4.3 allows a remote attacker to obtain sensitive... |
| CVE-2023-46104 | MEDIUM | 6.5 | 1.7% | Dec 19, 2023 | Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import data... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now