3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-28096
opensips General
4.5
MEDIUM
EPSS
1.0%
2023 CWE-401 1 PoC

OpenSIPS, a Session Initiation Protocol (SIP) server implementation, has a memory leak starting in the 2.3 branch and priot to versions 3.1.8 and 3.2.5. The memory leak was detected in the function `parse_mi_request` while performing coverage-guided fuzzing. This issue can be reproduced by sending multiple requests of the form `{"jsonrpc": "2.0","method": "log_le`. This malformed message was tested against an instance of OpenSIPS via FIFO transport layer and was found to increase the memory consumption over time. To abuse this memory leak, attackers need to reach the management interface (MI)

CVE-2023-0023
Bank Account Management (Manage Banks) General
4.5
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

In SAP Bank Account Management (Manage Banks) application, when a user clicks a smart link to navigate to another app, personal data is shown directly in the URL. They might get captured in log files, bookmarks, and so on disclosing sensitive data of the application.

CVE-2023-4108
Mattermost General
4.5
MEDIUM
EPSS
0.2%
2023 CWE-532 1 PoC

Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged

CVE-2023-33992
SAP Business Warehouse and SAP BW/4HANA General
4.5
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

The SAP BW BICS communication layer in SAP Business Warehouse and SAP BW/4HANA - version SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 730, SAP_BW 750, DW4CORE 100, DW4CORE 200, DW4CORE 300, may expose unauthorized cell values to the data response. To be able to exploit this, the user still needs authorizations on the query as well as on the keyfigure/measure level. The missing check only affects the data level.

CVE-2023-21518
Samsung SearchWidget General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications to start arbitrary activity.

CVE-2023-21430
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-125 1 PoC

An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR JAN-2023 Release 1 allows attacker to cause memory access fault.

CVE-2023-5255
Puppet Enterprise General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.

CVE-2023-20579
AMD Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics General
4.4
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability.

CVE-2023-2612
ubuntu-linux General
4.4
MEDIUM
EPSS
0.0%
2023 CWE-667 3 PoCs

Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when handling inode locking in some situations. A local attacker could use this to cause a denial of service (kernel deadlock).

CVE-2023-1486
WiseCleaner Wise Force Deleter General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

A vulnerability classified as problematic was found in Lespeed WiseCleaner Wise Force Deleter 1.5.3.54. This vulnerability affects the function 0x220004 in the library WiseUnlock64.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223372.

CVE-2023-30697
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2023 1 PoC

An improper input validation in IpcTxCfgSetSimlockPayload in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.

CVE-2023-5586
gpac/gpac General
4.4
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3.0-DEV.

CVE-2023-21435
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-200 1 PoC

Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address information via log.

CVE-2023-1453
Anti-Virus General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-284 2 PoCs

A vulnerability was found in Watchdog Anti-Virus 1.4.214.0. It has been rated as critical. Affected by this issue is the function 0x80002008 in the library wsdk-driver.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. VDB-223298 is the identifier assigned to this vulnerability.

CVE-2023-21488
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerablility in Tips prior to SMR May-2023 Release 1 allows local attackers to launch arbitrary activity in Tips.

CVE-2023-3013
gpac/gpac General
4.4
MEDIUM
EPSS
0.0%
2023 CWE-252 1 PoC

Unchecked Return Value in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-21460
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-287 1 PoC

Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.

CVE-2023-20812
MT6761, MT6762, MT6765, MT6768, MT6769, MT6781, MT6783, MT6785, MT6789, MT6833, MT6853, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6889, MT6891, MT6893, MT6895, MT6896, MT6983, MT6985, MT8365 General
4.4
MEDIUM
EPSS
0.0%
2023 1 PoC

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07944987; Issue ID: ALPS07944987.

CVE-2023-42756
Red Hat Enterprise Linux 9 General
4.4
MEDIUM
EPSS
0.0%
2023 CWE-362 1 PoC

A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP can lead to a kernel panic due to the invocation of `__ip_set_put` on a wrong `set`. This issue may allow a local user to crash the system.

CVE-2023-43572
Desktop BIOS General
4.4
MEDIUM
EPSS
0.0%
2023 CWE-126 1 PoC

A buffer over-read was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.