3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-42561
Samsung Mobile Devices General
7.1
HIGH
EPSS
0.2%
2023 1 PoC

Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.

CVE-2023-42492
v3.0.6433.1964 General
7.1
HIGH
EPSS
0.1%
2023 CWE-321 1 PoC

EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key

CVE-2023-3141
Kernel General
7.1
HIGH
EPSS
0.0%
2023 CWE-416 1 PoC

A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak.

CVE-2023-41704
OX App Suite General
7.1
HIGH
EPSS
0.5%
2023 CWE-79 1 PoC

Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing has been improved and resulting content is checked for malicious content. No publicly available exploits are known.

CVE-2023-3268
Kernel General
7.1
HIGH
EPSS
0.0%
2023 CWE-125 1 PoC

An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information.

CVE-2023-0818
gpac/gpac General
7.1
HIGH
EPSS
0.0%
2023 CWE-193 1 PoC

Off-by-one Error in GitHub repository gpac/gpac prior to v2.3.0-DEV.

CVE-2023-39215
Zoom Clients General
7.1
HIGH
EPSS
0.3%
2023 CWE-449 1 PoC

Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-3749
VideoEdge General
7.1
HIGH
EPSS
0.0%
2023 CWE-349 1 PoC

A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.

CVE-2023-53907
Backup Plugin General
7.1
HIGH
EPSS
0.4%
2023 CWE-22 1 PoC

Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backup Plugin that allows logged-in users to access arbitrary files. Attackers can exploit the plugin's download functionality by manipulating file path parameters to read sensitive system files through directory traversal.

CVE-2023-2239
microweber/microweber General
7.1
HIGH
EPSS
0.3%
2023 CWE-359 1 PoC

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository microweber/microweber prior to 1.3.4.

CVE-2023-1070
nilsteampassnet/teampass General
7.1
HIGH
EPSS
0.3%
2023 CWE-73 1 PoC

External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.

CVE-2023-4259
Zephyr General
7.1
HIGH
EPSS
0.2%
2023 CWE-120 1 PoC

Two potential buffer overflow vulnerabilities at the following locations in the Zephyr eS-WiFi driver source code.

CVE-2023-1385
Fire TV Stick 3rd gen General
7.1
HIGH
EPSS
0.2%
2023 CWE-330 1 PoC

Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthorized authentication to amzn.lightning services. This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS 7.6.3.3.

CVE-2023-3567
Red Hat Enterprise Linux 8 General
7.1
HIGH
EPSS
0.0%
2023 CWE-416 4 PoCs

A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information.

CVE-2023-5289
ikus060/rdiffweb General
7.1
HIGH
EPSS
0.1%
2023 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4.

CVE-2023-36533
Zoom SDK's General
7.1
HIGH
EPSS
0.4%
2023 CWE-772 1 PoC

Uncontrolled resource consumption in Zoom SDKs before 5.14.7 may allow an unauthenticated user to enable a denial of service via network access.

CVE-2023-6458
Mattermost General
7.1
HIGH
EPSS
0.5%
2023 CWE-74 1 PoC

Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traversal.

CVE-2023-34044
Workstation General
7.1
HIGH
EPSS
0.0%
2023 1 PoC

VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.

CVE-2023-4264
Zephyr General
7.1
HIGH
EPSS
0.2%
2023 CWE-120 1 PoC

Potential buffer overflow vulnerabilities n the Zephyr Bluetooth subsystem.

CVE-2023-20587
3rd Gen AMD EPYC™ Processors General
7.1
HIGH
EPSS
0.0%
2023 1 PoC

Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution.