5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-5406
Experion Server General
5.9
MEDIUM
EPSS
0.6%
2023 CWE-787 1 PoC

Server communication with a controller can lead to remote code execution using a specially crafted message from the controller. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-36532
Zoom Clients General
5.9
MEDIUM
EPSS
0.7%
2023 CWE-122 1 PoC

Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.

CVE-2023-3635
Software Genérico General
5.9
MEDIUM
EPSS
0.5%
2023 CWE-195 1 PoC

GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.

CVE-2023-4813
Red Hat Enterprise Linux 8 General
5.9
MEDIUM
EPSS
0.3%
2023 CWE-416 1 PoC

A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.

CVE-2023-43804
urllib3 Web
5.9
MEDIUM
EPSS
0.9%
2023 CWE-200 2 PoCs

urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.

CVE-2023-4778
gpac/gpac General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-21468
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper access control vulnerability in Telephony prior to SMR Apr-2023 Release 1 allows attackers to access files with escalated permission.

CVE-2023-42570
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control vulnerability in KnoxCustomManagerService prior to SMR Dec-2023 Release 1 allows attacker to access device SIM PIN.

CVE-2023-21421
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-280 1 PoC

Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2023 Release 1 allows attacker to access device SIM PIN.

CVE-2023-32890
MT2731, MT6767, MT6768, MT6769, MT6769T, MT6769Z, MT8666, MT8667, MT8765, MT8766, MT8768, MT8786, MT8788 General
5.9
MEDIUM
EPSS
0.3%
2023 1 PoC

In modem EMM, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01183647; Issue ID: MOLY01183647 (MSV-963).

CVE-2023-43628
GPSd General
5.9
MEDIUM
EPSS
0.2%
2023 CWE-191 2 PoCs

An integer underflow vulnerability exists in the NTRIP Stream Parsing functionality of GPSd 3.25.1~dev. A specially crafted network packet can lead to memory corruption. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-46445
Software Genérico Networking
5.9
MEDIUM
EPSS
0.4%
2023 1 PoC

An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation."

CVE-2023-47184
Admin Bar & Dashboard Access Control Web
5.9
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Proper Fraction LLC. Admin Bar & Dashboard Access Control plugin <= 1.2.8 versions.

CVE-2023-3316
libtiff General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path that requires permissions like /dev/null) while specifying zones.

CVE-2023-30876
Dave's WordPress Live Search Web Windows
5.9
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Dave Ross Dave's WordPress Live Search plugin <= 4.8.1 versions.

CVE-2023-28098
opensips General
5.9
MEDIUM
EPSS
0.4%
2023 CWE-20 1 PoC

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, a specially crafted Authorization header causes OpenSIPS to crash or behave in an unexpected way due to a bug in the function `parse_param_name()` . This issue was discovered while performing coverage guided fuzzing of the function parse_msg. The AddressSanitizer identified that the issue occurred in the function `q_memchr()` which is being called by the function `parse_param_name()`. This issue may cause erratic program behaviour or a server crash. It affects configurations containing fun

CVE-2023-24516
Pandora FMS Web
5.9
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) vulnerability in the Pandora FMS Special Days component allows an attacker to use it to steal the session cookie value of admin users easily with little user interaction. This issue affects Pandora FMS v767 version and prior versions on all platforms.

CVE-2023-21954
Java SE JDK and JRE Database
5.9
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalV

CVE-2023-21967
Java SE JDK and JRE Web Database
5.9
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Ora

CVE-2023-5407
C300 General
5.9
MEDIUM
EPSS
0.1%
2023 CWE-121 1 PoC

Controller denial of service due to improper handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning.