3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-20597
Ryzen™ 3000 Series Desktop Processors “Matisse” General
N/A
UNKNOWN
EPSS
0.1%
2023 CWE-824 1 PoC

Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.

CVE-2023-5575
Server General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Improper access control in the permission inheritance in Devolutions Server 2022.3.13.0 and earlier allows an attacker that compromised a low privileged user to access entries via a specific combination of permissions in the entry and in its parent.

CVE-2023-52603
Linux General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In the Linux kernel, the following vulnerability has been resolved: UBSAN: array-index-out-of-bounds in dtSplitRoot Syzkaller reported the following issue: oop0: detected capacity change from 0 to 32768 UBSAN: array-index-out-of-bounds in fs/jfs/jfs_dtree.c:1971:9 index -2 is out of range for type 'struct dtslot [128]' CPU: 0 PID: 3613 Comm: syz-executor270 Not tainted 6.0.0-syzkaller-09423-g493ffd6605b2 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/22/2022 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x1b1/0x28e lib/

CVE-2023-49313
Software Genérico General
N/A
UNKNOWN
EPSS
4.2%
2023 1 PoC

A dylib injection vulnerability in XMachOViewer 0.04 allows attackers to compromise integrity. By exploiting this, unauthorized code can be injected into the product's processes, potentially leading to remote control and unauthorized access to sensitive user data.

CVE-2023-40137
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In multiple functions of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-36622
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 2 PoCs

The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated administrators to inject arbitrary OS commands via the timezone parameter.

CVE-2023-49230
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
31.1%
2023 0 PoCs

An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals' configurations without prior authentication.

CVE-2023-20787
MT6739, MT6761, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6833, MT6853, MT6873, MT6877, MT6883, MT8167, MT8167S, MT8168, MT8321, MT8362A, MT8365 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In thermal, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07648734; Issue ID: ALPS07648734.

CVE-2023-52489
Linux General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In the Linux kernel, the following vulnerability has been resolved: mm/sparsemem: fix race in accessing memory_section->usage The below race is observed on a PFN which falls into the device memory region with the system memory configuration where PFN's are such that [ZONE_NORMAL ZONE_DEVICE ZONE_NORMAL]. Since normal zone start and end pfn contains the device memory PFN's as well, the compaction triggered will try on the device memory PFN's too though they end up in NOP(because pfn_to_online_page() returns NULL for ZONE_DEVICE memory sections). When from other core, the section mappings ar

CVE-2023-29735
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue found in edjing Mix v.7.09.01 for Android allows a local attacker to cause a denial of service via the database files.

CVE-2023-38356
Software Genérico General
N/A
UNKNOWN
EPSS
6.0%
2023 1 PoC

MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

CVE-2023-52277
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Royal RoyalTSX before 6.0.2.1 allows attackers to cause a denial of service (Heap Memory Corruption and application crash) or possibly have unspecified other impact via a long hostname in an RTSZ file, if the victim clicks on Test Connection. This occurs during SecureGatewayHost object processing in RAPortCheck.createNWConnection.

CVE-2023-45574
Software Genérico General
N/A
UNKNOWN
EPSS
22.6%
2023 1 PoC

Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the fn parameter of the file.data function.

CVE-2023-39005
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.

CVE-2023-46497
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the mkdirSync function in the folderCreate/createFolder.js endpoint.

CVE-2023-44807
Software Genérico General
N/A
UNKNOWN
EPSS
3.3%
2023 1 PoC

D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the cancelPing function.

CVE-2023-38632
Software Genérico General
N/A
UNKNOWN
EPSS
29.1%
2023 1 PoC

async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in tcpsocket.hpp when processing malformed TCP packets.

CVE-2023-38906
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue in TPLink Smart Bulb Tapo series L530 1.1.9, L510E 1.0.8, L630 1.0.3, P100 1.4.9, Smart Camera Tapo series C200 1.1.18, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the authentication code for the UDP message.

CVE-2023-39671
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2023 1 PoC

D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function FUN_0001be68.

CVE-2023-51201
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Sin descripción disponible.