3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-51795
Software Genérico General
8.0
HIGH
EPSS
0.1%
2023 2 PoCs

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showspectrum.c:1789:52 component in showspectrumpic_request_frame

CVE-2023-28909
Volkswagen MIB3 infotainment system MIB3 OI MQB General
8.0
HIGH
EPSS
0.2%
2023 CWE-190 2 PoCs

A specific flaw exists within the Bluetooth stack of the MIB3 unit. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow when receiving fragmented HCI packets on a channel. An attacker can leverage this vulnerability to bypass the MTU check on a channel with enabled fragmentation. Consequently, this can lead to a buffer overflow in upper layer profiles, which can be used to obtain remote code execution. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The lis

CVE-2023-24047
Software Genérico General
8.0
HIGH
EPSS
0.0%
2023 1 PoC

An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via use of weak hashing algorithm.

CVE-2023-47564
Qsync Central General
8.0
HIGH
EPSS
8.0%
2023 CWE-732 1 PoC

An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.15 ( 2024/01/04 ) and later Qsync Central 4.3.0.11 ( 2024/01/11 ) and later

CVE-2023-22726
act General
8.0
HIGH
EPSS
1.5%
2023 CWE-434 1 PoC

act is a project which allows for local running of github actions. The artifact server that stores artifacts from Github Action runs does not sanitize path inputs. This allows an attacker to download and overwrite arbitrary files on the host from a Github Action. This issue may lead to privilege escalation. The /upload endpoint is vulnerable to path traversal as filepath is user controlled, and ultimately flows into os.Mkdir and os.Open. The /artifact endpoint is vulnerable to path traversal as the path is variable is user controlled, and the specified file is ultimately returned by the server

CVE-2023-3491
fossbilling/fossbilling General
8.0
HIGH
EPSS
0.1%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3.

CVE-2023-21477
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.0%
2023 1 PoC

Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.

CVE-2023-30709
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.1%
2023 1 PoC

Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers launch activity with system privilege.

CVE-2023-4876
hamza417/inure General
7.9
HIGH
EPSS
0.1%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository hamza417/inure prior to build92.

CVE-2023-33865
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 3 PoCs

RenderDoc before 1.27 allows local privilege escalation via a symlink attack. It relies on the /tmp/RenderDoc directory regardless of ownership.

CVE-2023-40116
Android General
7.8
HIGH
EPSS
0.0%
2023 1 PoC

In onTaskAppeared of PipTaskOrganizer.java, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-4738
vim/vim General
7.8
HIGH
EPSS
0.0%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.

CVE-2023-27329
PDF Reader General
7.8
HIGH
EPSS
3.5%
2023 CWE-416 1 PoC

Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the cu

CVE-2023-1078
Linux kernel General
7.8
HIGH
EPSS
0.0%
2023 CWE-787 1 PoC

A flaw was found in the Linux Kernel in RDS (Reliable Datagram Sockets) protocol. The rds_rm_zerocopy_callback() uses list_entry() on the head of a list causing a type confusion. Local user can trigger this with rds_message_put(). Type confusion leads to `struct rds_msg_zcopy_info *info` actually points to something else that is potentially controlled by local user. It is known how to trigger this, which causes an out of bounds access, and a lock corruption.

CVE-2023-38111
PDF Reader General
7.8
HIGH
EPSS
1.8%
2023 CWE-416 1 PoC

Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the cu

CVE-2023-6932
Kernel General
7.8
HIGH
EPSS
0.0%
2023 CWE-416 3 PoCs

A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achieve local privilege escalation. A race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread. We recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1.

CVE-2023-42097
PDF Reader General
7.8
HIGH
EPSS
1.9%
2023 CWE-416 1 PoC

Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the cu

CVE-2023-42926
macOS General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

CVE-2023-41992
🔥 KEV macOS General
7.8
HIGH
EPSS
1.1%
2023 1 PoC

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CVE-2023-2008
Linux kernel udmabuf device driver General
7.8
HIGH
EPSS
1.8%
2023 CWE-129 1 PoC

A flaw was found in the Linux kernel's udmabuf device driver. The specific flaw exists within a fault handler. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an array. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel.