3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-32571
Software Genérico General
N/A
UNKNOWN
EPSS
76.9%
2023 3 PoCs

Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods including Where, Select, OrderBy is parsed.

CVE-2023-2991
Globalscape EFT General
N/A
UNKNOWN
EPSS
0.3%
2023 CWE-200 2 PoCs

Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Globalscape is installed on can be remotely determined via a "trial extension request" message

CVE-2023-6209
Firefox General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

CVE-2023-38198
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.

CVE-2023-34198
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in the filtering slot results in the usage of an object of the :any" type, which may have unexpected results for access control.

CVE-2023-43866
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2023 1 PoC

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard7 function.

CVE-2023-1916
libtiff General
N/A
UNKNOWN
EPSS
0.0%
2023 CWE-125 1 PoC

A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.

CVE-2023-34929
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A stack overflow in the AddMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2023-40889
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2023 2 PoCs

A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.

CVE-2023-43865
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2023 1 PoC

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanPPTP function.

CVE-2023-20808
MT9011, MT9022, MT9618, MT9649, MT9653 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In OPTEE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03645895; Issue ID: DTV03645895.

CVE-2023-23063
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
30.4%
2023 0 PoCs

Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFileContent.cgi.

CVE-2023-30451
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

In TYPO3 11.5.24, the filelist component allows attackers (who have access to the administrator panel) to read arbitrary files via directory traversal in the baseuri field, as demonstrated by POST /typo3/record/edit with ../../../ in data[sys_file_storage]*[data][sDEF][lDEF][basePath][vDEF].

CVE-2023-21251
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In onCreate of ConfirmDialog.java, there is a possible way to connect to VNP bypassing user's consent due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

CVE-2023-32212
Firefox General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

CVE-2023-39908
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may lead to disclosure of uninitialized and previously used memory.

CVE-2023-24134
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey3 parameter at /goform/WifiBasicSet.

CVE-2023-47323
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to administrators.

CVE-2023-39341
FFRI yarai General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

"FFRI yarai", "FFRI yarai Home and Business Edition" and their OEM products handle exceptional conditions improperly, which may lead to denial-of-service (DoS) condition. Affected products and versions are as follows: FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0, FFRI yarai Home and Business Edition version 1.4.0, InfoTrace Mark II Malware Protection (Mark II Zerona) versions 3.0.1 to 3.2.2, Zerona / Zerona PLUS versions 3.2.32 to 3.2.36, ActSecure χ versions 3.4.0 to 3.4.6 and 3.5.0, Dual Safe Powered by FFRI yarai version 1.4.1, EDR Plus Pack (Bundled FFRI yarai versions 3.4.0 to 3.4.6 and

CVE-2023-27952
macOS General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

A race condition was addressed with improved locking. This issue is fixed in macOS Ventura 13.3. An app may bypass Gatekeeper checks.