3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-28613
Software Genérico General
6.8
MEDIUM
EPSS
1.0%
2023 2 PoCs

An issue was discovered in Samsung Exynos Mobile Processor and Baseband Modem Processor for Exynos 1280, Exynos 2200, and Exynos Modem 5300. An integer overflow in IPv4 fragment handling can occur due to insufficient parameter validation when reassembling these fragments.

CVE-2023-21508
Samsung Blockchain Keystore General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-787 1 PoC

Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.

CVE-2023-20795
MT6739, MT6761, MT6762, MT6768, MT6769, MT6779, MT6781, MT6785, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6885, MT6886, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985, MT8321, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8791T, MT8797 General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07864900; Issue ID: ALPS07864900.

CVE-2023-34568
Software Genérico General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet.

CVE-2023-30689
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

Out-of-bounds Write in BuildOemEmbmsGetSigStrengthResponse of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

CVE-2023-30653
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.1%
2023 1 PoC

Out of bounds read and write in enableTspDevice of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.

CVE-2023-45078
BIOS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-125 1 PoC

A memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

CVE-2023-32489
PowerScale OneFS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-280 1 PoC

Dell PowerScale OneFS 8.2x -9.5x contains a privilege escalation vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, to bypass mode protections and gain elevated privileges.  

CVE-2023-42528
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper Input Validation vulnerability in ProcessNvBuffering of libsec-ril prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.

CVE-2023-43571
Desktop BIOS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-120 1 PoC

A buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

CVE-2023-45075
BIOS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-125 1 PoC

A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

CVE-2023-0745
YugabyteDB Anywhere General
6.7
MEDIUM
EPSS
0.3%
2023 CWE-23 1 PoC

The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary files through the backup upload endpoint by using path traversal characters. This vulnerability is associated with program files PlatformReplicationManager.Java. This issue affects YugabyteDB Anywhere: from 2.0.0.0 through 2.13.0.0

CVE-2023-34570
Software Genérico General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter devName at /goform/SetOnlineDevName.

CVE-2023-0977
Trellix Agent General
6.7
MEDIUM
EPSS
0.4%
2023 CWE-120 1 PoC

A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page heap in the macmnsvc process memory block resulting in the service becoming unavailable.

CVE-2023-43567
Desktop BIOS General
6.7
MEDIUM
EPSS
0.1%
2023 CWE-120 1 PoC

A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

CVE-2023-42133
POS terminals General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-276 1 PoC

PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must have shell access with system account privileges in order to exploit this vulnerability. A patch addressing this issue was included in firmware version PayDroid_8.1.0_Sagittarius_V11.1.61_20240226.

CVE-2023-43577
Desktop BIOS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-120 1 PoC

A buffer overflow was reported in the ReFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

CVE-2023-5078
ThinkPad BIOS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-1419 1 PoC

A vulnerability was reported in some ThinkPad BIOS that could allow a physical or local attacker with elevated privileges to tamper with BIOS firmware.

CVE-2023-30652
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.1%
2023 1 PoC

Out of bounds read and write in callrunTspCmdNoRead of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.