3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-29761
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue found in Sleep v.20230303 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the SharedPreference files.

CVE-2023-42545
Phone General
5.5
MEDIUM
EPSS
0.3%
2023 1 PoC

Use of implicit intent for sensitive communication vulnerability in Phone prior to versions 12.7.20.12 in Android 11, 13.1.48, 13.5.28 in Android 12, and 14.7.38 in Android 13 allows attackers to access location data.

CVE-2023-3772
Red Hat Enterprise Linux 8 General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-476 2 PoCs

A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service.

CVE-2023-23005
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2023 1 PoC

In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases in which a user can cause the alloc_memory_type error case to be reached.

CVE-2023-1640
Malware Fighter General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability classified as problematic was found in IObit Malware Fighter 9.4.0.776. This vulnerability affects the function 0x222010 in the library ObCallbackProcess.sys of the component IOCTL Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224020.

CVE-2023-24785
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue in Giorgio Tani peazip v.9.0.0 allows attackers to cause a denial of service via the End of Archive tag function of the peazip/pea UNPEA feature.

CVE-2023-41991
🔥 KEV iOS and iPadOS General
5.5
MEDIUM
EPSS
3.5%
2023 1 PoC

A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CVE-2023-29759
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue found in FlightAware v.5.8.0 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the database files.

CVE-2023-6105
Service Desk Plus General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-200 1 PoC

An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.

CVE-2023-30732
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control in system property prior to SMR Oct-2023 Release 1 allows local attacker to get CPU serial number.

CVE-2023-24577
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

McAfee Total Protection prior to 16.0.50 allows attackers to elevate user privileges due to Improper Link Resolution via registry keys. This could enable a user with lower privileges to execute unauthorized tasks.

CVE-2023-2731
libtiff General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service.

CVE-2023-26818
Software Genérico General
5.5
MEDIUM
EPSS
4.7%
2023 1 PoC

Telegram 9.3.1 and 9.4.0 allows attackers to access restricted files, microphone ,or video recording via the DYLD_INSERT_LIBRARIES flag.

CVE-2023-30722
Samsung Blockchain Keystore General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Protection Mechanism Failure in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.13.5 allows local attacker to execute arbitrary code.

CVE-2023-6560
kernel General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-823 1 PoC

An out-of-bounds memory access flaw was found in the io_uring SQ/CQ rings functionality in the Linux kernel. This issue could allow a local user to crash the system.

CVE-2023-1637
Kernel General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-226 1 PoC

A flaw that boot CPU could be vulnerable for the speculative execution behavior kind of attacks in the Linux kernel X86 CPU Power management options functionality was found in the way user resuming CPU from suspend-to-RAM. A local user could use this flaw to potentially get unauthorized access to some memory of the CPU similar to the speculative execution behavior kind of attacks.

CVE-2023-1492
Anti Virus Plus General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-404 2 PoCs

A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. It has been declared as problematic. This vulnerability affects the function 0x220019 in the library MaxProc64.sys of the component IoControlCode Handler. The manipulation of the argument SystemBuffer leads to denial of service. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. VDB-223378 is the identifier assigned to this vulnerability.

CVE-2023-2872
FlexiHub General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

A vulnerability classified as problematic has been found in FlexiHub 5.5.14691.0. This affects the function 0x220088 in the library fusbhub.sys of the component IoControlCode Handler. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229851. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-42548
Samsung Account General
5.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Use of implicit intent for sensitive communication vulnerability in startMandatoryCheckActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

CVE-2023-2875
Antivirus General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-476 3 PoCs

A vulnerability, which was classified as problematic, was found in eScan Antivirus 22.0.1400.2443. Affected is the function 0x22E008u in the library PROCOBSRVESX.SYS of the component IoControlCode Handler. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. VDB-229854 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.