3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-40600
EWWW Image Optimizer General ⚡ nuclei
5.3
MEDIUM
EPSS
46.9%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exactly WWW EWWW Image Optimizer. It works only when debug.log is turned on.This issue affects EWWW Image Optimizer: from n/a through 7.2.0.

CVE-2023-1007
Antivirus General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-284 2 PoCs

A vulnerability was found in Twister Antivirus 8.17. It has been declared as critical. This vulnerability affects the function 0x801120E4 in the library filmfd.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221740.

CVE-2023-30956
com.palantir.comments:comments General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-639 1 PoC

A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0.

CVE-2023-1537
answerdev/answer General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-294 1 PoC

Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-4511
Wireshark General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-835 1 PoC

BT SDP dissector infinite loop in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file

CVE-2023-37007
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Cancel` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

CVE-2023-53879
NVClient General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-121 2 PoCs

NVClient 5.0 contains a stack buffer overflow vulnerability in the user configuration contact field that allows attackers to crash the application. Attackers can overwrite 846 bytes of memory by pasting a crafted payload into the contact box, causing a denial of service condition.

CVE-2023-4227
ioLogik 4000 Series General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-489 1 PoC

A vulnerability has been identified in the ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which can be exploited by malicious actors to potentially gain unauthorized access to the product. This could lead to security breaches, data theft, and unauthorized manipulation of sensitive information. The vulnerability is attributed to the presence of an unauthorized service, which could potentially enable unauthorized access to the. device.

CVE-2023-6344
Court Case Management Plus General
5.3
MEDIUM
EPSS
1.6%
2023 CWE-287 1 PoC

Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate directories using the tiffserver/te003.aspx or te004.aspx 'ifolder' parameter. This behavior is related to the use of a deprecated version of Aquaforest TIFF Server, possibly 2.x. The vulnerable Aquaforest TIFF Server feature was removed on or around 2023-11-01. Insecure configuration issues in Aquaforest TIFF Server are identified separately as CVE-2023-6352. CVE-2023-6343 is related to or partially caused by CVE-2023-6352.

CVE-2023-32488
PowerScale OneFS General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-1230 1 PoC

Dell PowerScale OneFS, 8.2.x-9.5.0.x, contains an information disclosure vulnerability in NFS. A low privileged attacker could potentially exploit this vulnerability, leading to information disclosure.

CVE-2023-30858
emoji General
5.3
MEDIUM
EPSS
0.6%
2023 CWE-1333 1 PoC

The Denosaurs emoji package provides emojis for dinosaurs. Starting in version 0.1.0 and prior to version 0.3.0, the reTrimSpace regex has 2nd degree polynomial inefficiency, leading to a delayed response given a big payload. The issue has been patched in 0.3.0. As a workaround, avoid using the `replace`, `unemojify`, or `strip` functions.

CVE-2023-21485
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-926 1 PoC

Improper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.

CVE-2023-6343
Court Case Management Plus General
5.3
MEDIUM
EPSS
1.1%
2023 CWE-287 1 PoC

Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate and access sensitive files using the tiffserver/tssp.aspx 'FN' and 'PN' parameters. This behavior is related to the use of a deprecated version of Aquaforest TIFF Server, possibly 2.x. The vulnerable Aquaforest TIFF Server feature was removed on or around 2023-11-01. Insecure configuration issues in Aquaforest TIFF Server are identified separately as CVE-2023-6352. CVE-2023-6343 is similar to CVE-2020-9323. CVE-2023-6343 is related to or partially caused by CVE-2023-6352.

CVE-2023-1679
DriverGenius General
5.3
MEDIUM
EPSS
0.4%
2023 CWE-119 2 PoCs

A vulnerability classified as critical was found in DriverGenius 9.70.0.346. This vulnerability affects the function 0x9C406104/0x9C40A108 in the library mydrivers64.sys of the component IOCTL Handler. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224236.

CVE-2023-21466
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.0%
2023 1 PoC

PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access contentProvider without proper permission.

CVE-2023-37008
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contain a buffer overflow in the ASN.1 deserialization function of the S1AP handler. This buffer overflow causes type confusion in decoded fields, leading to invalid parsing and freeing of memory. An attacker may use this to crash an MME or potentially execute code in certain circumstances.

CVE-2023-47102
Software Genérico General
5.3
MEDIUM
EPSS
0.3%
2023 3 PoCs

UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid.

CVE-2023-31186
IX Workforce Engagement General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-204 1 PoC

Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy

CVE-2023-32492
PowerScale OneFS General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-276 1 PoC

Dell PowerScale OneFS 9.5.0.x contains an incorrect default permissions vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to information disclosure or allowing to modify files.