3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-40134
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In isFullScreen of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-21292
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In openContentUri of ActivityManagerService.java, there is a possible way for a third party app to obtain restricted files due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-37206
Firefox General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Uploading files which contain symlinks may have allowed an attacker to trick a user into submitting sensitive data to a malicious website. This vulnerability affects Firefox < 115.

CVE-2023-31293
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to obtain sensitive information and bypass profile restriction via improper access control in the Reader system user's web browser, allowing the journal to be displayed, despite the option being disabled.

CVE-2023-39909
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.

CVE-2023-30367
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Multi-Remote Next Generation Connection Manager (mRemoteNG) is free software that enables users to store and manage multi-protocol connection configurations to remotely connect to systems. mRemoteNG configuration files can be stored in an encrypted state on disk. mRemoteNG version <= v1.76.20 and <= 1.77.3-dev loads configuration files in plain text into memory (after decrypting them if necessary) at application start-up, even if no connection has been established yet. This allows attackers to access contents of configuration files in plain text through a memory dump and thus compromise user c

CVE-2023-36344
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue in Diebold Nixdorf Vynamic View Console v.5.3.1 and before allows a local attacker to execute arbitrary code via not restricting the search path for required DLLs and not verifying the signature.

CVE-2023-33264
Software Genérico General
N/A
UNKNOWN
EPSS
1.7%
2023 3 PoCs

In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.

CVE-2023-43860
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2023 1 PoC

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanNonLogin function.

CVE-2023-37635
Software Genérico General
N/A
UNKNOWN
EPSS
8.2%
2023 1 PoC

UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application.

CVE-2023-34669
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

TOTOLINK CP300+ V5.2cu.7594 contains a Denial of Service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system.

CVE-2023-41717
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Inappropriate file type control in Zscaler Proxy versions 3.6.1.25 and prior allows local attackers to bypass file download/upload restrictions.

CVE-2023-38571
macOS General
N/A
UNKNOWN
EPSS
10.5%
2023 1 PoC

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Big Sur 11.7.9, macOS Monterey 12.6.8, macOS Ventura 13.5. An app may be able to bypass Privacy preferences.

CVE-2023-24671
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

VX Search v13.8 and v14.7 was discovered to contain an unquoted service path vulnerability which allows attackers to execute arbitrary commands at elevated privileges via a crafted executable file.

CVE-2023-36624
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Loxone Miniserver Go Gen.2 through 14.0.3.28 allows an authenticated operating system user to escalate privileges via the Sudo configuration. This allows the elevated execution of binaries without a password requirement.

CVE-2023-45281
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file.

CVE-2023-5729
Firefox General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A malicious web site can enter fullscreen mode while simultaneously triggering a WebAuthn prompt. This could have obscured the fullscreen notification and could have been leveraged in a spoofing attack. This vulnerability affects Firefox < 119.

CVE-2023-20586
Radeon™ Software Crimson ReLive Edition General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

A potential vulnerability was reported in Radeon™ Software Crimson ReLive Edition which may allow escalation of privilege. Radeon™ Software Crimson ReLive Edition falls outside of the security support lifecycle and AMD does not plan to release any mitigations

CVE-2023-1234
Chrome General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Inappropriate implementation in Intents in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2023-40084
Android General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In run of MDnsSdListener.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.