3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-22490
git General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-59 1 PoC

Git is a revision control system. Using a specially-crafted repository, Git prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8 can be tricked into using its local clone optimization even when using a non-local transport. Though Git will abort local clones whose source `$GIT_DIR/objects` directory contains symbolic links, the `objects` directory itself may still be a symbolic link. These two may be combined to include arbitrary files based on known paths on the victim's filesystem within the malicious repository's working copy, allowing for data

CVE-2023-2875
Antivirus General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-476 3 PoCs

A vulnerability, which was classified as problematic, was found in eScan Antivirus 22.0.1400.2443. Affected is the function 0x22E008u in the library PROCOBSRVESX.SYS of the component IoControlCode Handler. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. VDB-229854 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-23002
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

In the Linux kernel before 5.16.3, drivers/bluetooth/hci_qca.c misinterprets the devm_gpiod_get_index_optional return value (expects it to be NULL in the error case, whereas it is actually an error pointer).

CVE-2023-43582
Zoom Clients General
5.5
MEDIUM
EPSS
0.2%
2023 CWE-939 1 PoC

Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

CVE-2023-1627
Antivirus General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability was found in Jianming Antivirus 16.2.2022.418. It has been rated as problematic. This issue affects some unknown processing in the library kvcore.sys of the component IoControlCode Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The identifier VDB-224009 was assigned to this vulnerability.

CVE-2023-29767
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue found in CrossX v.1.15.3 for Android allows a local attacker to cause a persistent denial of service via the database files.

CVE-2023-29758
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue found in Blue Light Filter v.1.5.5 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the SharedPreference files.

CVE-2023-0591
ubi_reader General
5.5
MEDIUM
EPSS
0.3%
2023 CWE-22 1 PoC

ubireader_extract_files is vulnerable to path traversal when run against specifically crafted UBIFS files, allowing the attacker to overwrite files outside of the extraction directory (provided the process has write access to that file or directory). This is due to the fact that a node name (dent_node.name) is considered trusted and joined to the extraction directory path during processing, then the node content is written to that joined path. By crafting a malicious UBIFS file with node names holding path traversal payloads (e.g. ../../tmp/outside.txt), it's possible to force ubi_reader to

CVE-2023-21036
Android General
5.5
MEDIUM
EPSS
0.2%
2023 1 PoC

In BitmapExport.java, there is a possible failure to truncate images due to a logic error in the code.Product: AndroidVersions: Android kernelAndroid ID: A-264261868References: N/A

CVE-2023-0597
Kernel General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-200 2 PoCs

A flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of X86 CPU data to memory was found in the way user can guess location of exception stack(s) or other important data. A local user could use this flaw to get access to some important data with expected location in memory.

CVE-2023-46316
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2023 1 PoC

In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not properly parse command lines.

CVE-2023-29753
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2023 1 PoC

An issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows a local attacker to cause a denial of service via the SharedPreference files.

CVE-2023-21445
The patch adds proper access control to use explicit intent. General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13) allows local attacker to write file with MyFiles privilege via implicit intent.

CVE-2023-0190
NVIDIA GPU Display Driver General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-476 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a NULL pointer dereference may lead to denial of service.

CVE-2023-23001
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2023 1 PoC

In the Linux kernel before 5.16.3, drivers/scsi/ufs/ufs-mediatek.c misinterprets the regulator_get return value (expects it to be NULL in the error case, whereas it is actually an error pointer).

CVE-2023-42550
Samsung Account General
5.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Use of implicit intent for sensitive communication vulnerability in startSignIn in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

CVE-2023-23586
Linux Kernel General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-416 1 PoC

Due to a vulnerability in the io_uring subsystem, it is possible to leak kernel memory information to the user process. timens_install calls current_is_single_threaded to determine if the current process is single-threaded, but this call does not consider io_uring's io_worker threads, thus it is possible to insert a time namespace's vvar page to process's memory space via a page fault. When this time namespace is destroyed, the vvar page is also freed, but not removed from the process' memory, and a next page allocated by the kernel will be still available from the user-space process and can l

CVE-2023-1493
Anti Virus Plus General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. It has been rated as problematic. This issue affects the function 0x220019 in the library MaxProctetor64.sys of the component IoControlCode Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223379.

CVE-2023-41991
🔥 KEV iOS and iPadOS General
5.5
MEDIUM
EPSS
3.5%
2023 1 PoC

A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CVE-2023-1644
Malware Fighter General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability was found in IObit Malware Fighter 9.4.0.776 and classified as problematic. Affected by this issue is the function 0x8018E010 in the library IMFCameraProtect.sys of the component IOCTL Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224024.