9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-43590
Zoom Rooms for macOS General
7.8
HIGH
EPSS
0.1%
2023 CWE-59 1 PoC

Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.

CVE-2023-30644
Samsung Mobile Devices General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

Stack out of bound write vulnerability in CdmaSmsParser of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

CVE-2023-34312
Software Genérico General
7.8
HIGH
EPSS
4.1%
2023 1 PoC

In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-process communication, which leads to a write-what-where condition.

CVE-2023-24980
Tecnomatix Plant Simulation General
7.8
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19790)

CVE-2023-24039
Software Genérico General
7.8
HIGH
EPSS
0.3%
2023 1 PoC

A stack-based buffer overflow in ParseColors in libXm in Common Desktop Environment 1.6 can be exploited by local low-privileged users via the dtprintinfo setuid binary to escalate their privileges to root on Solaris 10 systems. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-6040
linux General
7.8
HIGH
EPSS
0.0%
2023 CWE-125 1 PoC

An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family); While creating a new netfilter table, lack of a safeguard against invalid nf_tables family (pf) values within `nf_tables_newtable` function enables an attacker to achieve out-of-bounds access.

CVE-2023-38119
PDF Reader General
7.8
HIGH
EPSS
2.1%
2023 CWE-125 1 PoC

Foxit PDF Reader AcroForm signature Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of signature fields. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execut

CVE-2023-30257
Software Genérico General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

A buffer overflow in the component /proc/ftxxxx-debug of FiiO M6 Build Number v1.0.4 allows attackers to escalate privileges to root.

CVE-2023-4781
vim/vim General
7.8
HIGH
EPSS
0.0%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.

CVE-2023-36887
Microsoft Edge (Chromium-based) General
7.8
HIGH
EPSS
1.3%
2023 1 PoC

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVE-2023-38041
Secure Access Client General
7.8
HIGH
EPSS
0.3%
2023 1 PoC

A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system.

CVE-2023-51793
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 2 PoCs

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavutil/imgutils.c:353:9 in image_copy_plane.

CVE-2023-2609
vim/vim General
7.8
HIGH
EPSS
0.0%
2023 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531.

CVE-2023-21670
Snapdragon General
7.8
HIGH
EPSS
0.1%
2023 CWE-284 1 PoC

Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.

CVE-2023-6241
Midgard GPU Kernel Driver General
7.8
HIGH
EPSS
12.4%
2023 CWE-416 4 PoCs

Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to exploit a software race condition to perform improper memory processing operations. If the system’s memory is carefully prepared by the user, then this in turn cause a use-after-free.This issue affects Midgard GPU Kernel Driver: from r13p0 through r32p0; Bifrost GPU Kernel Driver: from r11p0 through r25p0; Valhall GPU Kernel Driver: from r19p0 through r25p0, from r29p0 th

CVE-2023-31873
Software Genérico General
7.8
HIGH
EPSS
0.4%
2023 1 PoC

Gin 0.7.4 allows execution of arbitrary code when a crafted file is opened, e.g., via require('child_process').

CVE-2023-1579
binutils General
7.8
HIGH
EPSS
0.1%
2023 CWE-119 1 PoC

Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.

CVE-2023-51042
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 1 PoC

In the Linux kernel before 6.4.12, amdgpu_cs_wait_all_fences in drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c has a fence use-after-free.

CVE-2023-6006
PaperCut NG, PaperCut MF General
7.8
HIGH
EPSS
0.0%
2023 CWE-250 1 PoC

This vulnerability potentially allows local attackers to escalate privileges on affected installations of PaperCut NG. An attacker must have local write access to the C Drive. In addition, Print Archiving must be enabled or the attacker needs to encounter a misconfigured system. This vulnerability does not apply to PaperCut NG installs that have Print Archiving enabled and configured as per the recommended set up procedure. This specific flaw exists within the pc-pdl-to-image process. The process loads an executable from an unsecured location. An attacker can leverage this vulnerability to esc

CVE-2023-37417
GTKWave General
7.8
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the GUI's interactive VCD parsing code.