9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-42561
Samsung Mobile Devices General
7.1
HIGH
EPSS
0.2%
2023 1 PoC

Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.

CVE-2023-41112
Software Genérico General
7.1
HIGH
EPSS
0.2%
2023 1 PoC

An issue was discovered in Samsung Mobile Processor, Wearable Processor, Automotive Processor, and Modem (Exynos 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, W920, Modem 5123, Modem 5300, and Auto T5123). A buffer copy, without checking the size of the input, can cause abnormal termination of a mobile phone. This occurs in the RLC task and RLC module.

CVE-2023-34044
Workstation General
7.1
HIGH
EPSS
0.0%
2023 1 PoC

VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.

CVE-2023-41704
OX App Suite General
7.1
HIGH
EPSS
0.5%
2023 CWE-79 1 PoC

Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing has been improved and resulting content is checked for malicious content. No publicly available exploits are known.

CVE-2023-1070
nilsteampassnet/teampass General
7.1
HIGH
EPSS
0.3%
2023 CWE-73 1 PoC

External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.

CVE-2023-3141
Kernel General
7.1
HIGH
EPSS
0.0%
2023 CWE-416 1 PoC

A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak.

CVE-2023-34458
mx-chain-go General
7.1
HIGH
EPSS
2.6%
2023 CWE-400 3 PoCs

mx-chain-go is the official implementation of the MultiversX blockchain protocol, written in golang. When executing a relayed transaction, if the inner transaction failed, it would have increased the inner transaction's sender account nonce. This could have contributed to a limited DoS attack on a targeted account. The fix is a breaking change so a new flag `RelayedNonceFixEnableEpoch` was needed. This was a strict processing issue while validating blocks on a chain. This vulnerability has been patched in version 1.4.17.

CVE-2023-4814
Data Loss Prevention Endpoint for Windows General
7.1
HIGH
EPSS
0.0%
2023 CWE-250 1 PoC

A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for which the user does not have permission to.

CVE-2023-6458
Mattermost General
7.1
HIGH
EPSS
0.5%
2023 CWE-74 1 PoC

Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traversal.

CVE-2023-1385
Fire TV Stick 3rd gen General
7.1
HIGH
EPSS
0.2%
2023 CWE-330 1 PoC

Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthorized authentication to amzn.lightning services. This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS 7.6.3.3.

CVE-2023-42492
v3.0.6433.1964 General
7.1
HIGH
EPSS
0.1%
2023 CWE-321 1 PoC

EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key

CVE-2023-4264
Zephyr General
7.1
HIGH
EPSS
0.2%
2023 CWE-120 1 PoC

Potential buffer overflow vulnerabilities n the Zephyr Bluetooth subsystem.

CVE-2023-0818
gpac/gpac General
7.1
HIGH
EPSS
0.0%
2023 CWE-193 1 PoC

Off-by-one Error in GitHub repository gpac/gpac prior to v2.3.0-DEV.

CVE-2023-36533
Zoom SDK's General
7.1
HIGH
EPSS
0.4%
2023 CWE-772 1 PoC

Uncontrolled resource consumption in Zoom SDKs before 5.14.7 may allow an unauthenticated user to enable a denial of service via network access.

CVE-2023-5289
ikus060/rdiffweb General
7.1
HIGH
EPSS
0.1%
2023 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4.

CVE-2023-53907
Backup Plugin General
7.1
HIGH
EPSS
0.4%
2023 CWE-22 1 PoC

Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backup Plugin that allows logged-in users to access arbitrary files. Attackers can exploit the plugin's download functionality by manipulating file path parameters to read sensitive system files through directory traversal.

CVE-2023-3749
VideoEdge General
7.1
HIGH
EPSS
0.0%
2023 CWE-349 1 PoC

A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.

CVE-2023-39215
Zoom Clients General
7.1
HIGH
EPSS
0.3%
2023 CWE-449 1 PoC

Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2024-7014
Telegram for Android General
7.1
HIGH
EPSS
17.5%
2024 CWE-20 2 PoCs

EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting versions 10.14.4 and older.

CVE-2024-40492
Software Genérico General
7.1
HIGH
EPSS
7.7%
2024 1 PoC

Cross Site Scripting vulnerability in Heartbeat Chat v.15.2.1 allows a remote attacker to execute arbitrary code via the setname function.