3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-1642
Malware Fighter General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability, which was classified as problematic, was found in IObit Malware Fighter 9.4.0.776. Affected is the function 0x222034/0x222038/0x22203C/0x222040 in the library ObCallbackProcess.sys of the component IOCTL Handler. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. VDB-224022 is the identifier assigned to this vulnerability.

CVE-2023-0593
yaffshiv General
5.5
MEDIUM
EPSS
0.3%
2023 CWE-22 1 PoC

A path traversal vulnerability affects yaffshiv YAFFS filesystem extractor. By crafting a malicious YAFFS file, an attacker could force yaffshiv to write outside of the extraction directory. This issue affects yaffshiv up to version 0.1 included, which is the most recent at time of publication.

CVE-2023-26157
libredwg General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-400 1 PoC

Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pages in decode_r2007.c.

CVE-2023-4211
🔥 KEV Midgard GPU Kernel Driver General
5.5
MEDIUM
EPSS
0.2%
2023 CWE-416 1 PoC

A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.

CVE-2023-42549
Samsung Account General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

CVE-2023-22996
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

In the Linux kernel before 5.17.2, drivers/soc/qcom/qcom_aoss.c does not release an of_find_device_by_node reference after use, e.g., with put_device.

CVE-2023-0592
jefferson General
5.5
MEDIUM
EPSS
0.3%
2023 CWE-22 1 PoC

A path traversal vulnerability affects jefferson's JFFS2 filesystem extractor. By crafting malicious JFFS2 files, attackers could force jefferson to write outside of the extraction directory.This issue affects jefferson: before 0.4.1.

CVE-2023-0908
Easy File Locker General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability, which was classified as problematic, was found in Xoslab Easy File Locker 2.2.0.184. This affects the function MessageNotifyCallback in the library xlkfs.sys. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier VDB-221457 was assigned to this vulnerability.

CVE-2023-20909
Android General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

In multiple functions of RunningTasks.java, there is a possible privilege escalation due to a missing privilege check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-243130512

CVE-2023-36629
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2023 2 PoCs

The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.

CVE-2023-22997
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

In the Linux kernel before 6.1.2, kernel/module/decompress.c misinterprets the module_get_next_page return value (expects it to be NULL in the error case, whereas it is actually an error pointer).

CVE-2023-28469
Software Genérico General
5.5
MEDIUM
EPSS
0.2%
2023 1 PoC

An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Valhall r29p0 through r42p0 before r43p0, and Arm's GPU Architecture Gen5 r41p0 through r42p0 before r43p0.

CVE-2023-23004
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2023 1 PoC

In the Linux kernel before 5.19, drivers/gpu/drm/arm/malidp_planes.c misinterprets the get_sg_table return value (expects it to be NULL in the error case, whereas it is actually an error pointer).

CVE-2023-2908
Libtiff General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

A null pointer dereference issue was found in Libtiff's tif_dir.c file. This issue may allow an attacker to pass a crafted TIFF image file to the tiffcp utility which triggers a runtime error that causes undefined behavior. This will result in an application crash, eventually leading to a denial of service.

CVE-2023-34256
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2023 1 PoC

An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from fs/ext4/super.c because ext4_group_desc_csum does not properly check an offset. NOTE: this is disputed by third parties because the kernel is not intended to defend against attackers with the stated "When modifying the block device while it is mounted by the filesystem" access.

CVE-2023-6548
🔥 KEV NetScaler ADC General
5.5
MEDIUM
EPSS
8.3%
2023 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.

CVE-2023-34982
SystemPlatform General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-73 1 PoC

This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.

CVE-2023-30086
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in tiffcp.c.

CVE-2023-29586
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2023 2 PoCs

Code Sector TeraCopy 3.9.7 does not perform proper access validation on the source folder during a copy operation. This leads to Arbitrary File Read by allowing any user to copy any directory in the system to a directory they control. NOTE: the Supplier disputes this because only admin users can copy arbitrary folders, and because the 143984 reference is about a different concern (unrelated to directory copying) that was fixed in 3.5b.

CVE-2023-1644
Malware Fighter General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability was found in IObit Malware Fighter 9.4.0.776 and classified as problematic. Affected by this issue is the function 0x8018E010 in the library IMFCameraProtect.sys of the component IOCTL Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224024.