3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-21459
Samsung Mobile Devices General
5.0
MEDIUM
EPSS
0.2%
2023 1 PoC

Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cause memory access fault.

CVE-2023-29108
ABAP Platform and SAP Web Dispatcher General
5.0
MEDIUM
EPSS
0.2%
2023 CWE-923 1 PoC

The IP filter in ABAP Platform and SAP Web Dispatcher - versions WEBDISP 7.85, 7.89, KERNEL 7.85, 7.89, 7.91, may be vulnerable by erroneous IP netmask handling. This may enable access to backend applications from unwanted sources.

CVE-2023-2629
pimcore/customer-data-framework General
5.0
MEDIUM
EPSS
0.0%
2023 CWE-1236 1 PoC

Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to 3.3.9.

CVE-2023-5536
Ubuntu Server General
5.0
MEDIUM
EPSS
0.0%
2023 1 PoC

A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their privilege to root without requiring a sudo password.

CVE-2023-29915
Software Genérico General
4.9
MEDIUM
EPSS
0.3%
2023 1 PoC

H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via CMD parameter at /goform/aspForm.

CVE-2023-29906
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the Edit_BasicSSID interface at /goform/aspForm.

CVE-2023-29912
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R200 R200V100R004 was discovered to contain a stack overflow via the DelvsList interface at /goform/aspForm.

CVE-2023-27801
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the DelDNSHnList interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.

CVE-2023-27802
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the EditvsList parameter at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.

CVE-2023-29914
Software Genérico General
4.9
MEDIUM
EPSS
0.3%
2023 1 PoC

H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm.

CVE-2023-29905
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the UpdateSnat interface at /goform/aspForm.

CVE-2023-34259
Software Genérico General ⚡ nuclei
4.9
MEDIUM
EPSS
93.1%
2023 1 PoC

Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read arbitrary files on the filesystem, even files that require root privileges. NOTE: this issue exists because of an incomplete fix for CVE-2020-23575.

CVE-2023-31347
3rd Gen AMD EPYC™ Processors General
4.9
MEDIUM
EPSS
0.0%
2023 1 PoC

Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC is enabled potentially resulting in a loss of guest integrity.  

CVE-2023-0888
Space Battery Pack SP with Wi-Fi General
4.9
MEDIUM
EPSS
0.6%
2023 CWE-95 2 PoCs

An improper neutralization of directives in dynamically evaluated code vulnerability in the WiFi Battery embedded web server in versions L90/U70 and L92/U92 can be used to gain administrative access to the WiFi communication module. An authenticated user, having access to both the medical device WiFi network (such as a biomedical engineering staff member) and the specific B.Braun Battery Pack SP with WiFi web server credentials, could get administrative (root) access on the infusion pump communication module. This could be used as a vector to start further attacks

CVE-2023-39199
Zoom Clients General
4.9
MEDIUM
EPSS
0.1%
2023 CWE-325 1 PoC

Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.

CVE-2023-29909
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the AddWlanMacList interface at /goform/aspForm.

CVE-2023-27808
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.

CVE-2023-29916
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the UpdateWanParams interface at /goform/aspForm.

CVE-2023-42559
Samsung Mobile Devices General
4.9
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system time.

CVE-2023-29913
Software Genérico General
4.9
MEDIUM
EPSS
0.3%
2023 1 PoC

H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the SetAPWifiorLedInfoById interface at /goform/aspForm.