3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-34117
Zoom Client SDK General
3.3
LOW
EPSS
0.1%
2023 CWE-23 1 PoC

Relative path traversal in the Zoom Client SDK before version 5.15.0 may allow an unauthorized user to enable information disclosure via local access.

CVE-2023-5551
Software Genérico General
3.3
LOW
EPSS
0.1%
2023 CWE-200 1 PoC

Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.

CVE-2023-1188
Webcam for Remote Desktop General
3.3
LOW
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability was found in FabulaTech Webcam for Remote Desktop 2.8.42. It has been classified as problematic. Affected is the function 0x222018 in the library ftwebcam.sys of the component IoControlCode Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222360.

CVE-2023-1186
Webcam for Remote Desktop General
3.3
LOW
EPSS
0.1%
2023 CWE-476 1 PoC

A vulnerability has been found in FabulaTech Webcam for Remote Desktop 2.8.42 and classified as problematic. This vulnerability affects the function 0x222010/0x222018 in the library ftwebcam.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. VDB-222358 is the identifier assigned to this vulnerability.

CVE-2023-38108
PDF Reader General
3.3
LOW
EPSS
0.4%
2023 CWE-125 1 PoC

Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with othe

CVE-2023-30703
Samsung Members General
3.3
LOW
EPSS
0.2%
2023 1 PoC

Improper URL validation vulnerability in Samsung Members prior to version 14.0.07.1 allows attackers to access sensitive information.

CVE-2023-38105
PDF Reader General
3.3
LOW
EPSS
0.4%
2023 CWE-125 1 PoC

Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with othe

CVE-2023-42093
PDF Reader General
3.3
LOW
EPSS
0.6%
2023 CWE-416 1 PoC

Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to

CVE-2023-38113
PDF Reader General
3.3
LOW
EPSS
0.5%
2023 CWE-416 1 PoC

Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to

CVE-2023-42098
PDF Reader General
3.3
LOW
EPSS
0.6%
2023 CWE-416 1 PoC

Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to

CVE-2023-40085
Android General
3.3
LOW
EPSS
0.0%
2023 1 PoC

In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-26427
OX App Suite General
3.2
LOW
EPSS
0.1%
2023 CWE-922 1 PoC

Default permissions for a properties file were too permissive. Local system users could read potentially sensitive information. We updated the default permissions for noreply.properties set during package installation. No publicly available exploits are known.

CVE-2023-44976
Rentdrv2 General
3.2
LOW
EPSS
0.0%
2023 CWE-782 1 PoC

Hangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes and possibly have unspecified other impact via DeviceIoControl with control code 0x22E010, as exploited in the wild in October 2023.

CVE-2023-20573
3rd Gen AMD EPYC™ Processors General
3.2
LOW
EPSS
0.1%
2023 2 PoCs

A privileged attacker can prevent delivery of debug exceptions to SEV-SNP guests potentially resulting in guests not receiving expected debug information.

CVE-2023-3862
Travelable Trek Management Solution General
3.1
LOW
EPSS
0.1%
2023 CWE-79 1 PoC

A vulnerability was found in Travelmate Travelable Trek Management Solution 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Comment Box Handler. The manipulation of the argument comment leads to cross site scripting. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. VDB-235214 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-34994
OAS Platform General
3.1
LOW
EPSS
0.1%
2023 CWE-770 1 PoC

An improper resource allocation vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to creation of an arbitrary directory. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-29111
Application Interface Framework (ODATA service) General
3.1
LOW
EPSS
0.4%
2023 CWE-200 1 PoC

The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized attacker can use the collected information possibly to exploit the component. As a result, an attacker can cause a low impact on the confidentiality of the application.

CVE-2023-4105
Mattermost General
3.1
LOW
EPSS
0.3%
2023 CWE-862 1 PoC

Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able to access and download the attachment of a deleted message

CVE-2023-4228
ioLogik 4000 Series General
3.1
LOW
EPSS
0.2%
2023 CWE-1004 1 PoC

A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and manipulation.

CVE-2023-29092
Software Genérico General
3.1
LOW
EPSS
0.1%
2023 1 PoC

An issue was discovered in Exynos Mobile Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, and Exynos 1080. Binding of a wrong resource can occur due to improper handling of parameters while binding a network interface.