5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-29759
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue found in FlightAware v.5.8.0 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the database files.

CVE-2023-27704
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Void Tools Everything lower than v1.4.1.1022 was discovered to contain a Regular Expression Denial of Service (ReDoS).

CVE-2023-2872
FlexiHub General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

A vulnerability classified as problematic has been found in FlexiHub 5.5.14691.0. This affects the function 0x220088 in the library fusbhub.sys of the component IoControlCode Handler. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229851. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-0593
yaffshiv General
5.5
MEDIUM
EPSS
0.3%
2023 CWE-22 1 PoC

A path traversal vulnerability affects yaffshiv YAFFS filesystem extractor. By crafting a malicious YAFFS file, an attacker could force yaffshiv to write outside of the extraction directory. This issue affects yaffshiv up to version 0.1 included, which is the most recent at time of publication.

CVE-2023-3773
Red Hat Enterprise Linux 9 General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-125 1 PoC

A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to cause a 4 byte out-of-bounds read of XFRMA_MTIMER_THRESH when parsing netlink attributes, leading to potential leakage of sensitive heap data to userspace.

CVE-2023-0592
jefferson General
5.5
MEDIUM
EPSS
0.3%
2023 CWE-22 1 PoC

A path traversal vulnerability affects jefferson's JFFS2 filesystem extractor. By crafting malicious JFFS2 files, attackers could force jefferson to write outside of the extraction directory.This issue affects jefferson: before 0.4.1.

CVE-2023-1631
Antivirus General
5.5
MEDIUM
EPSS
0.2%
2023 CWE-476 2 PoCs

A vulnerability, which was classified as problematic, was found in JiangMin Antivirus 16.2.2022.418. This affects the function 0x222010 in the library kvcore.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The identifier VDB-224013 was assigned to this vulnerability.

CVE-2023-34872
Software Genérico General
5.5
MEDIUM
EPSS
0.2%
2023 1 PoC

A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.

CVE-2023-2336
pimcore/pimcore General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-22 1 PoC

Path Traversal in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-51777
Software Genérico Windows
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error.

CVE-2023-1644
Malware Fighter General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability was found in IObit Malware Fighter 9.4.0.776 and classified as problematic. Affected by this issue is the function 0x8018E010 in the library IMFCameraProtect.sys of the component IOCTL Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224024.

CVE-2023-41991
🔥 KEV iOS and iPadOS General
5.5
MEDIUM
EPSS
3.5%
2023 1 PoC

A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CVE-2023-1493
Anti Virus Plus General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. It has been rated as problematic. This issue affects the function 0x220019 in the library MaxProctetor64.sys of the component IoControlCode Handler. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223379.

CVE-2023-24785
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue in Giorgio Tani peazip v.9.0.0 allows attackers to cause a denial of service via the End of Archive tag function of the peazip/pea UNPEA feature.

CVE-2023-22999
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

In the Linux kernel before 5.16.3, drivers/usb/dwc3/dwc3-qcom.c misinterprets the dwc3_qcom_create_urs_usb_platdev return value (expects it to be NULL in the error case, whereas it is actually an error pointer).

CVE-2023-21880
MySQL Server Database
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vect

CVE-2023-42551
Samsung Account General
5.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Use of implicit intent for sensitive communication vulnerability in startTncActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

CVE-2023-21465
Bixby Touch General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerability in BixbyTouch prior to version 3.2.02.5 in China models allows untrusted applications access local files.

CVE-2023-31023
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
5.5
MEDIUM
EPSS
0.0%
2023 CWE-822 1 PoC

NVIDIA Display Driver for Windows contains a vulnerability where an attacker may cause a pointer dereference of an untrusted value, which may lead to denial of service.

CVE-2023-6617
Simple Student Attendance System Web Database
5.5
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been classified as critical. Affected is an unknown function of the file attendance.php. The manipulation of the argument class_id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-247254 is the identifier assigned to this vulnerability.