3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-26485
cmark-gfm General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-400 1 PoC

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. This CVE covers quadratic complexity issues when parsing text which leads with either large numbers of `_` characters. This issue has been addressed in version 0.29.0.gfm.10. Users are advised to upgrade. Users unable to upgrade should validate that their input comes from trusted sources. ### Impact A polynomial time complexity issue in cmark-gfm may lead to unbounded re

CVE-2023-1679
DriverGenius General
5.3
MEDIUM
EPSS
0.4%
2023 CWE-119 2 PoCs

A vulnerability classified as critical was found in DriverGenius 9.70.0.346. This vulnerability affects the function 0x9C406104/0x9C40A108 in the library mydrivers64.sys of the component IOCTL Handler. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224236.

CVE-2023-37008
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contain a buffer overflow in the ASN.1 deserialization function of the S1AP handler. This buffer overflow causes type confusion in decoded fields, leading to invalid parsing and freeing of memory. An attacker may use this to crash an MME or potentially execute code in certain circumstances.

CVE-2023-47102
Software Genérico General
5.3
MEDIUM
EPSS
0.3%
2023 3 PoCs

UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid.

CVE-2023-32492
PowerScale OneFS General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-276 1 PoC

Dell PowerScale OneFS 9.5.0.x contains an incorrect default permissions vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to information disclosure or allowing to modify files.

CVE-2023-37012
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial UE Message` message missing a required `PLMN Identity` field to repeatedly crash the MME, resulting in denial of service.

CVE-2023-31186
IX Workforce Engagement General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-204 1 PoC

Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy

CVE-2023-1745
KMPlayer General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-427 2 PoCs

A vulnerability, which was classified as problematic, has been found in KMPlayer 4.2.2.73. This issue affects some unknown processing in the library SHFOLDER.dll. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The identifier VDB-224633 was assigned to this vulnerability.

CVE-2023-1258
Flow-X General
5.3
MEDIUM
EPSS
13.2%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.

CVE-2023-30956
com.palantir.comments:comments General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-639 1 PoC

A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0.

CVE-2023-4754
gpac/gpac General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-787 1 PoC

Out-of-bounds Write in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-0830
EasyNAS General
5.3
MEDIUM
EPSS
38.5%
2023 CWE-78 2 PoCs

A vulnerability classified as critical has been found in EasyNAS 1.1.0. Affected is the function system of the file /backup.pl. The manipulation leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

CVE-2023-1629
Antivirus General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-119 2 PoCs

A vulnerability classified as critical was found in JiangMin Antivirus 16.2.2022.418. Affected by this vulnerability is the function 0x222010 in the library kvcore.sys of the component IOCTL Handler. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224011.

CVE-2023-2840
gpac/gpac General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-30663
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper input validation vulnerability in OemPersonalizationSetLock in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds write.

CVE-2023-50373
Alt Manager General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

Missing Authorization vulnerability in WPSAAD Alt Manager alt-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Alt Manager: from n/a through <= 1.6.1.

CVE-2023-3398
jgraph/drawio General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3.

CVE-2023-36539
Zoom clients General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

CVE-2023-5514
eSOMS General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-209 1 PoC

The response messages received from the eSOMS report generation using certain parameter queries with full file path can be abused for enumerating the local file system structure.

CVE-2023-39217
Zoom SDK's General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-80 1 PoC

Improper input validation in Zoom SDK’s before 5.14.10 may allow an unauthenticated user to enable a denial of service via network access.