CVE-2023-2397
published 2023-04-28CVE-2023-2397: A vulnerability, which was classified as problematic, has been found in SourceCodester Simple Mobile Comparison Website 1.0. This issue affects some unknown…
PriorityP422medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
EPSS
0.58%
43.6th percentile
A vulnerability, which was classified as problematic, has been found in SourceCodester Simple Mobile Comparison Website 1.0. This issue affects some unknown processing of the file classes/Master.php?f=save_field. The manipulation of the argument Field Name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227675.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | >= 0 < 5.10.190 | 5.10.190 |
| linux | linux_kernel | >= 5.11.0 < 5.15.124 | 5.15.124 |
| linux | linux_kernel | >= 5.16.0 < 6.1.43 | 6.1.43 |
| linux | linux_kernel | >= 5.18.0 < 6.4.8 | 6.4.8 |
| simple_mobile_comparison_website_project | simple_mobile_comparison_website | — | — |
| sourcecodester | simple_mobile_comparison_website | — | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.3LOWAV:N/AC:L/Au:M/C:N/I:P/A:N
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
tty: n_gsm: fix UAF in gsm_cleanup_mux
osv·2025-12-09
CVE-2023-53805 tty: n_gsm: fix UAF in gsm_cleanup_mux
tty: n_gsm: fix UAF in gsm_cleanup_mux
In the Linux kernel, the following vulnerability has been resolved:
tty: n_gsm: fix UAF in gsm_cleanup_mux
In gsm_cleanup_mux() the 'gsm->dlci' pointer was not cleaned properly,
leaving it a dangling pointer after gsm_dlci_release.
This leads to use-after-free where 'gsm->dlci[0]' are freed and accessed
by the subsequent gsm_cleanup_mux().
Such is the case in the following call trace:
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x1e3/0x2cb lib/dump_stack.c:106
print_address_description+0x63/0x3b0 mm/kasan/report.c:248
__kasan_report mm/kasan/report.c:434 [inline]
kasan_report+0x16b/0x1c0 mm/kasan/report.c:451
gsm_cleanup_mux+0x76a/0x850 drivers/tty/n_gsm.c:2397
gsm_config drivers/tty/n_gsm.c:2653 [inline]
gsmld_ioctl+0xaae/0x15b0 dr
GHSA
GHSA-5c33-qwmr-4c4r: A vulnerability, which was classified as problematic, has been found in SourceCodester Simple Mobile Comparison Website 1
ghsa_unreviewed·2023-04-29
CVE-2023-2397 [LOW] CWE-79 GHSA-5c33-qwmr-4c4r: A vulnerability, which was classified as problematic, has been found in SourceCodester Simple Mobile Comparison Website 1
A vulnerability, which was classified as problematic, has been found in SourceCodester Simple Mobile Comparison Website 1.0. This issue affects some unknown processing of the file classes/Master.php?f=save_field. The manipulation of the argument Field Name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227675.
Red Hat
tcpdump: Crafted .pcap file may lead to Denial of Service
vendor_redhat·2024-04-12·CVSS 6.2
CVE-2024-2397 [MEDIUM] CWE-835 tcpdump: Crafted .pcap file may lead to Denial of Service
tcpdump: Crafted .pcap file may lead to Denial of Service
Due to a bug in packet data buffers management, the PPP printer in tcpdump can enter an infinite loop when reading a crafted DLT_PPP_SERIAL .pcap savefile. This problem does not affect any tcpdump release, but it affected the git master branch from 2023-06-05 to 2024-03-21.
A flaw was found in tcpdump. Trying to print content from a maliciously crafted .pcap file may lead to an infinite loop, resulting in a denial of service. This issue is considered low severity; for a successful attack to happen, a user must open a crafted file, and it will only crash a single user's execution of tcpdump.
Package: libpcap (Red Hat Enterprise Linux 10) - Not affected
Package: tcpdump (Red Hat Enterprise Linux 10) - Not affected
Package: libpca
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-28
Published