5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-0908
Easy File Locker General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability, which was classified as problematic, was found in Xoslab Easy File Locker 2.2.0.184. This affects the function MessageNotifyCallback in the library xlkfs.sys. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier VDB-221457 was assigned to this vulnerability.

CVE-2023-42549
Samsung Account General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

CVE-2023-22997
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

In the Linux kernel before 6.1.2, kernel/module/decompress.c misinterprets the module_get_next_page return value (expects it to be NULL in the error case, whereas it is actually an error pointer).

CVE-2023-23455
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2023 1 PoC

atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results).

CVE-2023-5682
OA Web Database
5.5
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability has been found in Tongda OA 2017 and classified as critical. This vulnerability affects unknown code of the file general/hr/training/record/delete.php. The manipulation of the argument RECORD_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-243058 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-31021
vGPU driver and Cloud gaming driver Cloud Windows
5.5
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a malicious user in the guest VM can cause a NULL-pointer dereference, which may lead to denial of service.

CVE-2023-29532
Firefox Windows
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.

CVE-2023-1677
DriverGenius General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability was found in DriverGenius 9.70.0.346. It has been rated as problematic. Affected by this issue is the function 0x9c40a0c8/0x9c40a0dc/0x9c40a0e0/0x9c40a0d8/0x9c4060d4/0x9c402004/0x9c402088/0x9c40208c/0x9c4060d0/0x9c4060cc/0x9c4060c4/0x9c402084 in the library mydrivers64.sys of the component IOCTL Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. VDB-224234 is the identifier assigned to this vulnerability.

CVE-2023-31022
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
5.5
MEDIUM
EPSS
0.1%
2023 CWE-476 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a NULL-pointer dereference may lead to denial of service.

CVE-2023-4211
🔥 KEV Midgard GPU Kernel Driver General
5.5
MEDIUM
EPSS
0.2%
2023 CWE-416 1 PoC

A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.

CVE-2023-30086
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in tiffcp.c.

CVE-2023-28147
Software Genérico General
5.5
MEDIUM
EPSS
0.2%
2023 1 PoC

An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Midgard r29p0 through r32p0, Bifrost r17p0 through r42p0 before r43p0, Valhall r19p0 through r42p0 before r43p0, and Arm's GPU Architecture Gen5 r41p0 through r42p0 before r43p0.

CVE-2023-1643
Malware Fighter General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-404 2 PoCs

A vulnerability has been found in IObit Malware Fighter 9.4.0.776 and classified as problematic. Affected by this vulnerability is the function 0x8001E000/0x8001E004/0x8001E018/0x8001E01C/0x8001E024/0x8001E040 in the library ImfHpRegFilter.sys of the component IOCTL Handler. The manipulation leads to denial of service. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224023.

CVE-2023-36576
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
0.5%
2023 CWE-190 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2023-42545
Phone General
5.5
MEDIUM
EPSS
0.3%
2023 1 PoC

Use of implicit intent for sensitive communication vulnerability in Phone prior to versions 12.7.20.12 in Android 11, 13.1.48, 13.5.28 in Android 12, and 14.7.38 in Android 13 allows attackers to access location data.

CVE-2023-38140
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
0.2%
2023 CWE-908 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2023-1492
Anti Virus Plus General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-404 2 PoCs

A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. It has been declared as problematic. This vulnerability affects the function 0x220019 in the library MaxProc64.sys of the component IoControlCode Handler. The manipulation of the argument SystemBuffer leads to denial of service. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. VDB-223378 is the identifier assigned to this vulnerability.

CVE-2023-30732
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control in system property prior to SMR Oct-2023 Release 1 allows local attacker to get CPU serial number.

CVE-2023-28271
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
0.4%
2023 CWE-200 1 PoC

Windows Kernel Memory Information Disclosure Vulnerability

CVE-2023-3665
Trellix Endpoint Security General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-74 1 PoC

A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via environment variables, leading to denial of service and or the execution of arbitrary code.