3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-34046
Fusion General
6.7
MEDIUM
EPSS
0.1%
2023 1 PoC

VMware Fusion(13.x prior to 13.5) contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when installing an upgrade. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed or being installed for the first time.

CVE-2023-32494
PowerScale OneFS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-274 1 PoC

Dell PowerScale OneFS, 8.0.x-9.5.x, contains an improper handling of insufficient privileges vulnerability. A local privileged attacker could potentially exploit this vulnerability, leading to elevation of privilege and affect in compliance mode also.

CVE-2023-20816
MT6580, MT6739, MT6761, MT6765, MT6768, MT6779, MT6781, MT6833, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985 General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453589; Issue ID: ALPS07453589.

CVE-2023-21451
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.1%
2023 CWE-20 1 PoC

A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allows attacker to cause memory corruptions.

CVE-2023-42528
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper Input Validation vulnerability in ProcessNvBuffering of libsec-ril prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.

CVE-2023-20815
MT6580, MT6739, MT6761, MT6765, MT6768, MT6779, MT6781, MT6833, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985 General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453587; Issue ID: ALPS07453587.

CVE-2023-28907
Volkswagen MIB3 infotainment system MIB3 OI MQB General
6.7
MEDIUM
EPSS
0.1%
2023 CWE-284 2 PoCs

There is no memory isolation between CPU cores of the MIB3 infotainment. This fact allows an attacker with access to the main operating system to compromise the CPU core responsible for CAN message processing. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.

CVE-2023-30651
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.1%
2023 1 PoC

Out of bounds read and write in callgetTspsysfs of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.

CVE-2023-34570
Software Genérico General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter devName at /goform/SetOnlineDevName.

CVE-2023-45076
BIOS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-125 1 PoC

A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

CVE-2023-51797
Software Genérico General
6.7
MEDIUM
EPSS
0.0%
2023 2 PoCs

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:722:24 in showwaves_filter_frame

CVE-2023-43578
Desktop BIOS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-120 1 PoC

A buffer overflow was reported in the SmiFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

CVE-2023-43576
Desktop BIOS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-120 1 PoC

A buffer overflow was reported in the WMISwSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

CVE-2023-43573
Desktop BIOS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-120 1 PoC

A buffer overflow was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

CVE-2023-32490
PowerScale OneFS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-269 1 PoC

Dell PowerScale OneFS 8.2x -9.5x contains an improper privilege management vulnerability. A high privilege local attacker could potentially exploit this vulnerability, leading to system takeover.

CVE-2023-53874
GOM Player General
6.7
MEDIUM
EPSS
0.1%
2023 CWE-120 1 PoC

GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows attackers to crash the application. Attackers can overwrite the preset name with 260 'A' characters to trigger a buffer overflow and cause application instability.

CVE-2023-30440
PowerVM Hypervisor General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 through FW1020.30, and FW1030.00 through FW1030.10 could allow a local attacker with control a partition that has been assigned SRIOV virtual function (VF) to cause a denial of service to a peer partition or arbitrary data corruption. IBM X-Force ID: 253175.

CVE-2023-21244
Android General
6.7
MEDIUM
EPSS
0.0%
2023 2 PoCs

In visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-30693
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

Out-of-bounds Write in DoOemFactorySendFactoryBypassCommand of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

CVE-2023-20630
MT6580, MT6735, MT6739, MT6761, MT6763, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6853, MT6855, MT6873, MT6885, MT6893, MT6895, MT6983, MT8167, MT8168, MT8666, MT8675 General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

In usb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628505; Issue ID: ALPS07628505.