CVE-2023-4874

CVSS v3 Score
6.5
Medium

Vulnerability Description

Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12

CVSS:6.5(Medium)

A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows...

CVSS:5.7(Medium)

Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12

CVSS:7.5(High)

Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service....

CVSS:7.5(High)

A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The component uses pd.read_csv to process input values, which can accept compressed ...

CVSS:7.5(High)

A vulnerability in the HTML parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to an issue in...

CVSS:5.4(Medium)

A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploiting URL encoding. This flaw can lead to Denial of Service (DoS) as an authentica...