3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-6867
Firefox ESR General
N/A
UNKNOWN
EPSS
0.9%
2023 1 PoC

The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.

CVE-2023-27133
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

TSplus Remote Work 16.0.0.0 has weak permissions for .exe, .js, and .html files under the %PROGRAMFILES(X86)%\TSplus-RemoteWork\Clients\www folder. This may enable privilege escalation if a different local user modifies a file. NOTE: CVE-2023-31067 and CVE-2023-31068 are only about the TSplus Remote Access product, not the TSplus Remote Work product.

CVE-2023-20782
MT6580, MT6731, MT6735, MT6737, MT6739, MT6753, MT6757, MT6757C, MT6757CD, MT6757CH, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985, MT8185, MT8321, MT8385, MT8666, MT8667, MT8673, MT8675, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8797 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In keyinstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07550104; Issue ID: ALPS07550103.

CVE-2023-51012
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanGateway parameter’ of the setLanConfig interface of the cstecgi .cgi.

CVE-2023-33565
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Sin descripción disponible.

CVE-2023-35668
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In visitUris of Notification.java, there is a possible way to display images from another user due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-39139
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file.

CVE-2023-39144
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Element55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext.

CVE-2023-34853
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable.

CVE-2023-20588
EPYC™ 7001 Processors General
N/A
UNKNOWN
EPSS
6.7%
2023 1 PoC

A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. 

CVE-2023-52737
Linux General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In the Linux kernel, the following vulnerability has been resolved: btrfs: lock the inode in shared mode before starting fiemap Currently fiemap does not take the inode's lock (VFS lock), it only locks a file range in the inode's io tree. This however can lead to a deadlock if we have a concurrent fsync on the file and fiemap code triggers a fault when accessing the user space buffer with fiemap_fill_next_extent(). The deadlock happens on the inode's i_mmap_lock semaphore, which is taken both by fsync and btrfs_page_mkwrite(). This deadlock was recently reported by syzbot and triggers a trac

CVE-2023-41108
Software Genérico General
N/A
UNKNOWN
EPSS
2.2%
2023 2 PoCs

TEF portal 2023-07-17 is vulnerable to authenticated remote code execution.

CVE-2023-36166
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-20786
MT2713, MT6580, MT6739, MT6761, MT6765, MT6768, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6855, MT6873, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6983, MT6985, MT8167, MT8167S, MT8168, MT8175, MT8188, MT8195, MT8362A, MT8365, MT8673 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767811; Issue ID: ALPS07767811.

CVE-2023-31465
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.5%
2023 1 PoC

An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is possible to find the getsamplebacklog call. Some query parameters are passed directly in the URL and named arg[x], with x an integer starting from 1; it is possible to modify arg[2] to insert Bash code that will be executed directly by the server.

CVE-2023-20806
MT2713, MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8673 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In hcp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07537437.

CVE-2023-45253
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, allows attackers to manipulate files and escalate privileges via RollingFileAppender.DeleteFile method performed by the log4net library.

CVE-2023-26612
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field in SetParentsControlInfo.

CVE-2023-29734
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

An issue found in edjing Mix v.7.09.01 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the database.

CVE-2023-33567
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Sin descripción disponible.