3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-3304
admidio/admidio General
5.9
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.

CVE-2023-4778
gpac/gpac General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-21468
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper access control vulnerability in Telephony prior to SMR Apr-2023 Release 1 allows attackers to access files with escalated permission.

CVE-2023-4722
gpac/gpac General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-190 1 PoC

Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-5407
C300 General
5.9
MEDIUM
EPSS
0.1%
2023 CWE-121 1 PoC

Controller denial of service due to improper handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-50125
Software Genérico General
5.9
MEDIUM
EPSS
0.2%
2023 1 PoC

A default engineer password set on the Hozard alarm system (Alarmsysteem) v1.0 allows an attacker to bring the alarm system to a disarmed state.

CVE-2023-36917
SAP BusinessObjects Business Intelligence Platform General
5.9
MEDIUM
EPSS
0.1%
2023 CWE-307 1 PoC

SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to bypass the victim’s old password via brute force, due to unrestricted rate limit for password change functionality. Although the attack has no impact on integrity loss or system availability, this could lead to an attacker to completely takeover a victim’s account.

CVE-2023-42570
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control vulnerability in KnoxCustomManagerService prior to SMR Dec-2023 Release 1 allows attacker to access device SIM PIN.

CVE-2023-21421
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-280 1 PoC

Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2023 Release 1 allows attacker to access device SIM PIN.

CVE-2023-49083
cryptography General
5.9
MEDIUM
EPSS
0.9%
2023 CWE-476 1 PoC

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for any application attempting to deserialize a PKCS7 blob/certificate. The consequences extend to potential disruptions in system availability and stability. This vulnerability has been patched in version 41.0.6.

CVE-2023-4721
gpac/gpac General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-5406
Experion Server General
5.9
MEDIUM
EPSS
0.6%
2023 CWE-787 1 PoC

Server communication with a controller can lead to remote code execution using a specially crafted message from the controller. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-4756
gpac/gpac General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-121 1 PoC

Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-6566
microweber/microweber General
5.9
MEDIUM
EPSS
0.1%
2023 CWE-840 1 PoC

Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.

CVE-2023-32890
MT2731, MT6767, MT6768, MT6769, MT6769T, MT6769Z, MT8666, MT8667, MT8765, MT8766, MT8768, MT8786, MT8788 General
5.9
MEDIUM
EPSS
0.3%
2023 1 PoC

In modem EMM, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01183647; Issue ID: MOLY01183647 (MSV-963).

CVE-2023-5405
Experion Server General
5.9
MEDIUM
EPSS
0.1%
2023 CWE-787 1 PoC

Server information leak for the CDA Server process memory can occur when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-4682
gpac/gpac General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-43628
GPSd General
5.9
MEDIUM
EPSS
0.2%
2023 CWE-191 2 PoCs

An integer underflow vulnerability exists in the NTRIP Stream Parsing functionality of GPSd 3.25.1~dev. A specially crafted network packet can lead to memory corruption. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-3316
libtiff General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path that requires permissions like /dev/null) while specifying zones.

CVE-2023-21455
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.2%
2023 CWE-287 1 PoC

Improper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of unencrypted message.