5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-30695
Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 Networking Windows
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

Out-of-bounds Write vulnerability in SSHDCPAPP TA prior to "SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023" in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allows local attacker to execute arbitrary code.

CVE-2023-28141
Cloud Agent Cloud Windows
6.7
MEDIUM
EPSS
0.1%
2023 CWE-59 1 PoC

An NTFS Junction condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.8.0.31. Attackers may write files to arbitrary locations via a local attack vector. This allows attackers to assume the privileges of the process, and they may delete or otherwise on unauthorized files, allowing for the potential modification or deletion of sensitive files limited only to that specific directory/file object. This vulnerability is bounded to the time of installation/uninstallation and can only be exploited locally. At the time of this disclosure, versions before 4.0 are cla

CVE-2023-21508
Samsung Blockchain Keystore General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-787 1 PoC

Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.

CVE-2023-45078
BIOS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-125 1 PoC

A memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

CVE-2023-5847
Nessus Windows
6.7
MEDIUM
EPSS
0.1%
2023 CWE-269 1 PoC

Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate privileges on Windows and Linux hosts.

CVE-2023-41793
Pandora FMS General
6.7
MEDIUM
EPSS
0.1%
2023 CWE-35 1 PoC

: Path Traversal vulnerability in Pandora FMS on all allows Path Traversal. This vulnerability allowed changing directories and creating files and downloading them outside the allowed directories. This issue affects Pandora FMS: from 700 through <776.

CVE-2023-21969
SQL Developer Database
6.7
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in Oracle SQL Developer (component: Installation). Supported versions that are affected are Prior to 23.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle SQL Developer executes to compromise Oracle SQL Developer. Successful attacks of this vulnerability can result in takeover of Oracle SQL Developer. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVE-2023-49721
LXD General
6.7
MEDIUM
EPSS
0.0%
2023 3 PoCs

An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.

CVE-2023-25134
Software Genérico Windows
6.7
MEDIUM
EPSS
0.1%
2023 1 PoC

McAfee Total Protection prior to 16.0.50 may allow an adversary (with full administrative access) to modify a McAfee specific Component Object Model (COM) in the Windows Registry. This can result in the loading of a malicious payload.

CVE-2023-20809
MT5583, MT5691, MT5695, MT9010, MT9011, MT9012, MT9016, MT9020, MT9021, MT9022, MT9030, MT9031, MT9032, MT9215, MT9216, MT9218, MT9220, MT9221, MT9222, MT9255, MT9256, MT9266, MT9269, MT9285, MT9286, MT9288, MT9600, MT9602, MT9610, MT9611, MT9612, MT9613, MT9615, MT9617, MT9629, MT9630, MT9631, MT9632, MT9636, MT9638, MT9639, MT9650, MT9652, MT9666, MT9667, MT9669, MT9670, MT9671, MT9675, MT9685, MT9686, MT9688 General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03751198; Issue ID: DTV03751198.

CVE-2023-28907
Volkswagen MIB3 infotainment system MIB3 OI MQB General
6.7
MEDIUM
EPSS
0.1%
2023 CWE-284 2 PoCs

There is no memory isolation between CPU cores of the MIB3 infotainment. This fact allows an attacker with access to the main operating system to compromise the CPU core responsible for CAN message processing. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.

CVE-2023-30693
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

Out-of-bounds Write in DoOemFactorySendFactoryBypassCommand of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

CVE-2023-21244
Android General
6.7
MEDIUM
EPSS
0.0%
2023 2 PoCs

In visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-20817
MT6580, MT6739, MT6761, MT6765, MT6768, MT6779, MT6781, MT6833, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985 General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453600; Issue ID: ALPS07453600.

CVE-2023-43569
Desktop BIOS General
6.7
MEDIUM
EPSS
0.1%
2023 CWE-120 1 PoC

A buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. 

CVE-2023-30739
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

Arbitrary File Descriptor Write vulnerability in libsec-ril prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.

CVE-2023-20043
Cisco CX Cloud Agent Networking Cloud
6.7
MEDIUM
EPSS
0.1%
2023 CWE-708 1 PoC

A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. This vulnerability is due to insecure file permissions. An attacker could exploit this vulnerability by calling the script with sudo. A successful exploit could allow the attacker to take complete control of the affected device.

CVE-2023-30653
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.1%
2023 1 PoC

Out of bounds read and write in enableTspDevice of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.

CVE-2023-43571
Desktop BIOS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-120 1 PoC

A buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

CVE-2023-0745
YugabyteDB Anywhere General
6.7
MEDIUM
EPSS
0.3%
2023 CWE-23 1 PoC

The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary files through the backup upload endpoint by using path traversal characters. This vulnerability is associated with program files PlatformReplicationManager.Java. This issue affects YugabyteDB Anywhere: from 2.0.0.0 through 2.13.0.0