3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-49607
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-754 1 PoC

Mattermost fails to validate the type of the "reminder" body request parameter allowing an attacker to crash the Playbook Plugin when updating the status dialog.

CVE-2023-45806
discourse General
4.3
MEDIUM
EPSS
4.0%
2023 CWE-1333 1 PoC

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, if a user has been quoted and uses a `|` in their full name, they might be able to trigger a bug that generates a lot of duplicate content in all the posts they've been quoted by updating their full name again. Version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches contain a patch for this issue. No known workaround exists, although one can stop the "bleeding" by ensuring u

CVE-2023-24499
Butterfly Button plugin General
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Butterfly Button plugin may leave traces of its use on user's device. Since it is used for reporting domestic problems, this may lead to spouse knowing about its use.

CVE-2023-3786
Komet General
4.3
MEDIUM
EPSS
0.0%
2023 CWE-284 2 PoCs

A vulnerability classified as problematic has been found in Aures Komet up to 20230509. This affects an unknown part of the component Kiosk Mode. The manipulation leads to improper access controls. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier VDB-235053 was assigned to this vulnerability.

CVE-2023-3585
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-400 1 PoC

Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially crafted boards link.

CVE-2023-26434
OX App Suite General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue POP3 service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted POP3 server response to reasonable length/size. No publicly available exploits are known.

CVE-2023-25750
Firefox General
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulnerability affects Firefox < 111.

CVE-2023-30955
com.palantir.workspace:workspace General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-602 1 PoC

A security defect was identified in Foundry workspace-server that enabled a user to bypass an authorization check and view settings related to 'Developer Mode'. This enabled users with insufficient privilege the ability to view and interact with Developer Mode settings in a limited capacity. A fix was deployed with workspace-server 7.7.0.

CVE-2023-4119
LMS General
4.3
MEDIUM
EPSS
2.6%
2023 CWE-79 1 PoC

A vulnerability has been found in Academy LMS 6.0 and classified as problematic. This vulnerability affects unknown code of the file /academy/home/courses. The manipulation of the argument query/sort_by leads to cross site scripting. The attack can be initiated remotely. VDB-235966 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-3593
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdown input.

CVE-2023-30685
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mode.

CVE-2023-45874
Software Genérico General
4.3
MEDIUM
EPSS
0.3%
2023 2 PoCs

An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).

CVE-2023-28159
Firefox General
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The fullscreen notification could have been hidden on Firefox for Android by using download popups, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 111.

CVE-2023-40703
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Mattermost fails to properly limit the characters allowed in different fields of a block in Mattermost Boards allowing a attacker to consume excessive resources, possibly leading to Denial of Service, by patching the field of a block using a specially crafted string. 

CVE-2023-39204
Zoom Clients General
4.3
MEDIUM
EPSS
0.3%
2023 CWE-120 1 PoC

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

CVE-2023-49874
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest to update the tasks of a private playbook run if they know the run ID.

CVE-2023-6894
Intercom Broadcasting System General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-200 1 PoC

A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been classified as problematic. This affects an unknown part of the file access/html/system.html of the component Log File Handler. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-248253 was assigned to this vulnerability.

CVE-2023-25748
Firefox General
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

By displaying a prompt with a long description, the fullscreen notification could have been hidden, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 111.

CVE-2023-2358
Pentaho Business Analytics Server General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-257 1 PoC

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.5.0.0 and 9.3.0.4, including 8.3.x.x, saves passwords of the Hadoop Copy Files step in plaintext. 

CVE-2023-6298
iText General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-129 1 PoC

A vulnerability classified as problematic was found in Apryse iText 8.0.2. This vulnerability affects the function main of the file PdfDocument.java. The manipulation leads to improper validation of array index. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The identifier of this vulnerability is VDB-246124. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. A statement published afterwards explains that the exception is not a vu