5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-54334
Explorer32++ General
7.0
HIGH
EPSS
0.1%
2023 CWE-121 1 PoC

Explorer32++ 1.3.5.531 contains a buffer overflow vulnerability in Structured Exception Handler (SEH) records that allows attackers to execute arbitrary code. Attackers can exploit the vulnerability by providing a long file name argument over 396 characters to corrupt the SEH chain and potentially execute malicious code.

CVE-2023-53902
WebsiteBaker Web
7.0
HIGH
EPSS
0.9%
2023 CWE-22 1 PoC

WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary files by manipulating directory path parameters. Attackers can send crafted GET requests to /admin/media/delete.php with directory traversal sequences to delete files outside the intended directory.

CVE-2023-0834
Workforce Access General
7.0
HIGH
EPSS
0.2%
2023 CWE-732 1 PoC

Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege Escalation.This issue affects Workforce Access: from 6.12 before 8.1.

CVE-2023-35824
Software Genérico General
7.0
HIGH
EPSS
0.0%
2023 1 PoC

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in dm1105_remove in drivers/media/pci/dm1105/dm1105.c.

CVE-2023-42753
Red Hat Enterprise Linux 7 General
7.0
HIGH
EPSS
0.0%
2023 CWE-787 3 PoCs

An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decrement a memory buffer out-of-bound. This issue may allow a local user to crash the system or potentially escalate their privileges on the system.

CVE-2023-5249
Bifrost GPU Kernel Driver General
7.0
HIGH
EPSS
0.1%
2023 CWE-416 1 PoC

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper memory processing operations to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn cause a use-after-free.This issue affects Bifrost GPU Kernel Driver: from r35p0 through r40p0; Valhall GPU Kernel Driver: from r35p0 through r40p0.

CVE-2023-46813
Software Genérico General
7.0
HIGH
EPSS
0.3%
2023 2 PoCs

An issue was discovered in the Linux kernel before 6.5.9, exploitable by local users with userspace access to MMIO registers. Incorrect access checking in the #VC handler and instruction emulation of the SEV-ES emulation of MMIO accesses could lead to arbitrary write access to kernel memory (and thus privilege escalation). This depends on a race condition through which userspace can replace an instruction before the #VC handler reads it.

CVE-2023-22660
Ichitaro General
7.0
HIGH
EPSS
0.4%
2023 CWE-122 2 PoCs

A heap-based buffer overflow vulnerability exists in the way Ichitaro version 2022 1.0.1.57600 processes certain LayoutBox stream record types. A specially crafted document can cause a buffer overflow, leading to memory corruption, which can result in arbitrary code execution.To trigger this vulnerability, the victim would need to open a malicious, attacker-created document.

CVE-2023-29007
git General
7.0
HIGH
EPSS
0.7%
2023 CWE-74 3 PoCs

Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, a specially crafted `.gitmodules` file with submodule URLs that are longer than 1024 characters can used to exploit a bug in `config.c::git_config_copy_or_rename_section_in_file()`. This bug can be used to inject arbitrary configuration into a user's `$GIT_DIR/config` when attempting to remove the configuration section associated with that submodule. When the attacker injects configuration values which specify executables to run (such as `core.pager`,

CVE-2023-4677
Pandora FMS General
7.0
HIGH
EPSS
0.1%
2023 CWE-287 1 PoC

Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs directory for cron log backups. The contents of these log files can then be abused to authenticate to the application as an administrator. This issue affects Pandora FMS <= 772.

CVE-2023-21739
Windows 10 Version 1809 Windows
7.0
HIGH
EPSS
0.4%
2023 CWE-591 1 PoC

Windows Bluetooth Driver Elevation of Privilege Vulnerability

CVE-2023-25394
Software Genérico General
7.0
HIGH
EPSS
0.0%
2023 1 PoC

Videostream macOS app 0.5.0 and 0.4.3 has a Race Condition. The Updater privileged script attempts to update Videostream every 5 hours.

CVE-2023-36427
Windows 10 Version 1809 Windows
7.0
HIGH
EPSS
9.9%
2023 1 PoC

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2023-28218
Windows 10 Version 1809 Windows
7.0
HIGH
EPSS
30.4%
2023 CWE-122 1 PoC

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2023-42820
jumpserver Web
7.0
HIGH
EPSS
62.8%
2023 CWE-200 4 PoCs

JumpServer is an open source bastion host. This vulnerability is due to exposing the random number seed to the API, potentially allowing the randomly generated verification codes to be replayed, which could lead to password resets. If MFA is enabled users are not affect. Users not using local authentication are also not affected. Users are advised to upgrade to either version 2.28.19 or to 3.6.5. There are no known workarounds or this issue.

CVE-2023-32614
ImageGear General
7.0
HIGH
EPSS
0.2%
2023 CWE-124 1 PoC

A heap-based buffer overflow vulnerability exists in the create_png_object functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-5091
Valhall GPU Kernel Driver General
7.0
HIGH
EPSS
0.1%
2023 CWE-416 1 PoC

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU processing operations to gain access to already freed memory. This issue affects Valhall GPU Kernel Driver: from r37p0 through r40p0.

CVE-2023-32832
MT6883, MT6885, MT6889, MT6893, MT6895, MT6983, MT6985, MT8797, MT8798 General
7.0
HIGH
EPSS
0.0%
2023 1 PoC

In video, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08235273; Issue ID: ALPS08235273.

CVE-2023-5184
Zephyr General
7.0
HIGH
EPSS
0.3%
2023 CWE-120 1 PoC

Two potential signed to unsigned conversion errors and buffer overflow vulnerabilities at the following locations in the Zephyr IPM drivers.

CVE-2023-21896
Solaris Operating System Database
7.0
HIGH
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).