3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-29929
Software Genérico General
7.5
HIGH
EPSS
2.8%
2023 2 PoCs

Buffer Overflow vulnerability found in Kemptechnologies Loadmaster before v.7.2.60.0 allows a remote attacker to casue a denial of service via the libkemplink.so, isreverse library.

CVE-2023-26141
sidekiq General
7.5
HIGH
EPSS
0.4%
2023 CWE-400 1 PoC

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.

CVE-2023-26925
Software Genérico General
7.5
HIGH
EPSS
0.9%
2023 2 PoCs

An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-882 1.30. A specially crafted network request can lead to the disclosure of sensitive information.

CVE-2023-45892
Software Genérico General
7.5
HIGH
EPSS
1.0%
2023 1 PoC

An issue discovered in the Order and Invoice pages in Floorsight Insights Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.

CVE-2023-34400
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. In case of parsing file, service try to define header inside the file and convert it to null-terminated string. If character is missed, will return null pointer.

CVE-2023-26152
static-server General
7.5
HIGH
EPSS
0.8%
2023 CWE-22 1 PoC

All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function of server.js.

CVE-2023-31115
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. Incorrect resource transfer between spheres can cause changes to the activation mode of RCS via a crafted application.

CVE-2023-29740
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 2 PoCs

An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause a denial of service attack by manipulating the database.

CVE-2023-5245
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 CWE-22 1 PoC

FileUtil.extract() enumerates all zip file entries and extracts each file without validating whether file paths in the archive are outside the intended directory. When creating an instance of TensorflowModel using the saved_model format and an exported tensorflow model, the apply() function invokes the vulnerable implementation of FileUtil.extract(). Arbitrary file creation can directly lead to code execution

CVE-2023-5392
C300 General
7.5
HIGH
EPSS
0.1%
2023 CWE-1295 1 PoC

C300 information leak due to an analysis feature which allows extracting more memory over the network than required by the function. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-29726
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

The Call Blocker application 6.6.3 for Android incorrectly opens a key component that an attacker can use to inject large amounts of dirty data into the application's database. When the application starts, it loads the data from the database into memory. Once the attacker injects too much data, the application triggers an OOM error and crashes, resulting in a persistent denial of service.

CVE-2023-49981
Software Genérico General
7.5
HIGH
EPSS
0.6%
2023 2 PoCs

A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.

CVE-2023-24709
Software Genérico General
7.5
HIGH
EPSS
32.1%
2023 4 PoCs

An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters.

CVE-2023-31893
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 2 PoCs

Telefnica Brasil Vivo Play (IPTV) Firmware: 2023.04.04.01.06.15 is vulnerable to Denial of Service (DoS) via DNS Recursion.

CVE-2023-6245
Candid General
7.5
HIGH
EPSS
0.1%
2023 CWE-835 1 PoC

The Candid library causes a Denial of Service while parsing a specially crafted payload with 'empty' data type. For example, if the payload is `record { * ; empty }` and the canister interface expects `record { * }` then the Rust candid decoder treats empty as an extra field required by the type. The problem with the type empty is that the candid Rust library wrongly categorizes empty as a recoverable error when skipping the field and thus causing an infinite decoding loop. Canisters using affected versions of candid are exposed to denial of service by causing the decoding to run indefi

CVE-2023-49338
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 2 PoCs

Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.

CVE-2023-22512
Confluence Data Center General
7.5
HIGH
EPSS
14.8%
2023 2 PoCs

This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, this vulnerability allows an unauthenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a vulnerable host (Confluence instance) connected to a network, which has no impact to confidentiality, no impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest

CVE-2023-27191
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 2 PoCs

An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the SharedPreference files.

CVE-2023-25369
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS is vulnerable to Denial of Service on the user interface triggered by malformed SCPI command.

CVE-2023-21444
Samsung Flow for PC General
7.5
HIGH
EPSS
0.1%
2023 CWE-326 1 PoC

Improper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted messages or inject commands.