DE EN FR
hlukh.ch Stand: 2026-02-25T21:01:10.471Z · week: 2023-W15

Sicherheitswarnungen

Kuratiert aus öffentlich verfügbaren Advisories. Fokus: Sichtbarkeit, Einordnung und schneller Export – ohne Clickbait.

Neueste Warnungen
CVE-2023-28260
.NET DLL Hijacking Remote Code Execution Vulnerability
2026‑02‑20 · CVE-2023-28260
MSRC 2026‑02‑20 Hoch
CVE-2023-1079
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-1079
MSRC 2026‑02‑20 Mittel
CVE-2023-28448
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-28448
MSRC 2026‑02‑20 Hoch
CVE-2022-25882
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2022-25882
MSRC 2026‑02‑20 Hoch
CVE-2023-1513
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-1513
MSRC 2026‑02‑20 Niedrig
CVE-2023-28642
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-28642
MSRC 2026‑02‑20 Hoch
CVE-2023-25809
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-25809
MSRC 2026‑02‑20 Mittel
CVE-2022-4899
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2022-4899
MSRC 2026‑02‑20 Hoch
CVE-2022-40133
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2022-40133
MSRC 2026‑02‑20 Mittel
CVE-2023-23006
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-23006
MSRC 2026‑02‑20 Mittel
CVE-2023-28486
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-28486
MSRC 2026‑02‑20 Mittel
CVE-2023-1355
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-1355
MSRC 2026‑02‑20 Mittel
CVE-2022-2869
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2022-2869
MSRC 2026‑02‑20 Mittel
CVE-2023-28425
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-28425
MSRC 2026‑02‑20 Mittel
CVE-2021-45955
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2021-45955
MSRC 2026‑02‑20 Kritisch
CVE-2021-45957
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2021-45957
MSRC 2026‑02‑20 Kritisch
CVE-2023-1281
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-1281
MSRC 2026‑02‑20 Hoch
CVE-2022-48424
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2022-48424
MSRC 2026‑02‑20 Hoch
CVE-2023-27561
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-27561
MSRC 2026‑02‑20 Hoch
CVE-2020-8908
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2020-8908
MSRC 2026‑02‑20 Niedrig
CVE-2022-37601
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2022-37601
MSRC 2026‑02‑20 Kritisch
CVE-2023-22997
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-22997
MSRC 2026‑02‑20 Mittel
CVE-2023-23005
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-23005
MSRC 2026‑02‑20 Mittel
CVE-2023-28487
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-28487
MSRC 2026‑02‑20 Mittel
CVE-2022-2867
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2022-2867
MSRC 2026‑02‑20 Mittel
CVE-2022-2868
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2022-2868
MSRC 2026‑02‑20 Mittel
CVE-2022-46176
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2022-46176
MSRC 2026‑02‑20 Mittel
CVE-2022-48423
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2022-48423
MSRC 2026‑02‑20 Hoch
CVE-2023-1390
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-1390
MSRC 2026‑02‑20 Hoch
CVE-2023-26604
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑20 · CVE-2023-26604
MSRC 2026‑02‑20 Hoch
CVE-2023-1916
A flaw was found in tiffcrop a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.
2026‑02‑20 · CVE-2023-1916
MSRC 2026‑02‑20 Mittel
CVE-2023-1989
A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. In this flaw a call to btsdio_remove with an unfinished job may cause a race problem leading to a UAF on hdev devices.
2026‑02‑20 · CVE-2023-1989
MSRC 2026‑02‑20 Hoch
CVE-2023-29469
An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document xmlDictComputeFastKey in dict.c can produce non-deterministic values leading to various logic and memory errors such as a double free. This behavior occurs because there is an attempt to use the first byte of an empty string and any value is possible (not solely the '\0' value).
2026‑02‑20 · CVE-2023-29469
MSRC 2026‑02‑20 Mittel
CVE-2021-28235
Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.
2026‑02‑20 · CVE-2021-28235
MSRC 2026‑02‑20 Kritisch
CVE-2023-28312
Azure Machine Learning Information Disclosure Vulnerability
2026‑02‑20 · CVE-2023-28312
MSRC 2026‑02‑20 Mittel
CVE-2023-28300
Azure Service Connector Security Feature Bypass Vulnerability
2026‑02‑20 · CVE-2023-28300
MSRC 2026‑02‑20 Hoch
CVE-2023-24538
Backticks not treated as string delimiters in html/template
2026‑02‑20 · CVE-2023-24538
MSRC 2026‑02‑20 Kritisch
CVE-2020-19695
Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c function.
2026‑02‑20 · CVE-2020-19695
MSRC 2026‑02‑20 Kritisch
CVE-2020-19692
Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file.
2026‑02‑20 · CVE-2020-19692
MSRC 2026‑02‑20 Kritisch
CVE-2023-31484
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
2026‑02‑20 · CVE-2023-31484
MSRC 2026‑02‑20 Hoch
CVE-2023-28231
DHCP Server Service Remote Code Execution Vulnerability
2026‑02‑20 · CVE-2023-28231
MSRC 2026‑02‑20 Hoch
CVE-2023-30630
Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because for example execution of Dmidecode via Sudo is plausible.
2026‑02‑20 · CVE-2023-30630
MSRC 2026‑02‑20 Hoch
CVE-2023-24534
Excessive memory allocation in net/http and net/textproto
2026‑02‑20 · CVE-2023-24534
MSRC 2026‑02‑20 Hoch
CVE-2023-24536
Excessive resource consumption in net/http, net/textproto and mime/multipart
2026‑02‑20 · CVE-2023-24536
MSRC 2026‑02‑20 Hoch
CVE-2023-31486
HTTP::Tiny before 0.083 a Perl core module since 5.13.9 and available standalone on CPAN has an insecure default TLS configuration where users must opt in to verify certificates.
2026‑02‑20 · CVE-2023-31486
MSRC 2026‑02‑20 Hoch
CVE-2023-21100
In inflate of inflate.c there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-242544249
2026‑02‑20 · CVE-2023-21100
MSRC 2026‑02‑20 Hoch
CVE-2023-28484
In libxml2 before 2.10.4 parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.
2026‑02‑20 · CVE-2023-28484
MSRC 2026‑02‑20 Mittel
CVE-2023-29383
In Shadow 4.13 it is possible to inject control characters into fields provided to the SUID program chfn (change finger). Although it is not possible to exploit this directly (e.g. adding a new user fails because \n is in the block list) it is possible to misrepresent the /etc/passwd file when viewed. Use of \r manipulations and Unicode characters to work around blocking of the : character make it possible to give the impression that a new user has been added. In other words an adversary may be able to convince a system administrator to take the system offline (an indirect social-engineered denial of service) by demonstrating that "cat /etc/passwd" shows a rogue user account.
2026‑02‑20 · CVE-2023-29383
MSRC 2026‑02‑20 Niedrig
CVE-2023-24537
Infinite loop in parsing in go/scanner
2026‑02‑20 · CVE-2023-24537
MSRC 2026‑02‑20 Hoch
CVE-2023-28219
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
2026‑02‑20 · CVE-2023-28219
MSRC 2026‑02‑20 Hoch
Seite 1