40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-46585
MicroStation CONNECT General
7.8
HIGH
EPSS
0.7%
2021 CWE-121 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15379.

CVE-2025-23386
openSUSE Tumbleweed General
7.8
HIGH
EPSS
0.1%
2025 CWE-276 1 PoC

A Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed package gerbera allows the service user gerbera to escalate to root.,This issue affects gerbera on openSUSE Tumbleweed before 2.5.0-1.1.

CVE-2021-31455
Reader General
7.8
HIGH
EPSS
3.1%
2021 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of XFA forms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13100.

CVE-2024-7725
PDF Reader General
7.8
HIGH
EPSS
3.3%
2024 CWE-416 1 PoC

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current proce

CVE-2024-46971
Graphics DDK General
7.8
HIGH
EPSS
0.1%
2024 CWE-416 1 PoC

Software installed and run as a non-privileged user may conduct GPU system calls to read and write freed physical memory from the GPU.

CVE-2021-30303
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking General
7.8
HIGH
EPSS
0.0%
2021 1 PoC

Possible buffer overflow due to lack of buffer length check when segmented WMI command is received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

CVE-2024-23749
Software Genérico General
7.8
HIGH
EPSS
0.3%
2024 2 PoCs

KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitization and validation, failure to escape special characters, and insecure system calls (at lines 2369-2390). This allows an attacker to add inputs inside the filename variable, leading to arbitrary code execution.

CVE-2024-0210
Wireshark General
7.8
HIGH
EPSS
0.1%
2024 CWE-674 1 PoC

Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file

CVE-2024-31960
Software Genérico General
7.8
HIGH
EPSS
0.2%
2024 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 1480, Exynos 2400. The xclipse amdgpu driver has a reference count bug. This can lead to a use after free.

CVE-2024-0582
Software Genérico General
7.8
HIGH
EPSS
0.7%
2024 CWE-416 9 PoCs

A memory leak flaw was found in the Linux kernel’s io_uring functionality in how a user registers a buffer ring with IORING_REGISTER_PBUF_RING, mmap() it, and then frees it. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVE-2021-30323
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
7.8
HIGH
EPSS
0.0%
2021 1 PoC

Improper validation of maximum size of data write to EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2024-47900
Graphics DDK General
7.8
HIGH
EPSS
0.1%
2024 CWE-823 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to access OOB kernel memory.

CVE-2021-34929
View General
7.8
HIGH
EPSS
0.5%
2021 CWE-787 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. Crafted data in a JT file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14907.

CVE-2024-30322
PDF Reader General
7.8
HIGH
EPSS
2.2%
2024 CWE-416 1 PoC

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current proce

CVE-2022-1898
vim/vim General
7.8
HIGH
EPSS
0.3%
2022 CWE-416 2 PoCs

Use After Free in GitHub repository vim/vim prior to 8.2.

CVE-2020-23438
Software Genérico General
7.8
HIGH
EPSS
0.1%
2020 1 PoC

Wondershare filmora 9.2.11 is affected by Trojan Dll hijacking leading to privilege escalation.

CVE-2024-9254
PDF Reader General
7.8
HIGH
EPSS
1.6%
2024 CWE-416 1 PoC

Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the cu

CVE-2024-37000
AutoCAD General
7.8
HIGH
EPSS
0.3%
2024 CWE-787 1 PoC

A maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.

CVE-2024-53920
Software Genérico General
7.8
HIGH
EPSS
0.1%
2024 1 PoC

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)

CVE-2024-25446
Software Genérico General
7.8
HIGH
EPSS
0.1%
2024 1 PoC

An issue in the HuginBase::PTools::setDestImage function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image.