5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-30709
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.1%
2023 1 PoC

Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers launch activity with system privilege.

CVE-2023-39212
Zoom Rooms for Windows Windows
7.9
HIGH
EPSS
0.0%
2023 CWE-144 1 PoC

Untrusted search path in Zoom Rooms for Windows before version 5.15.5 may allow an authenticated user to enable a denial of service via local access.

CVE-2023-40283
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 2 PoCs

An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled.

CVE-2023-21749
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
1.5%
2023 CWE-20 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-51794
Software Genérico General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/af_stereowiden.c:120:69.

CVE-2023-24985
Tecnomatix Plant Simulation General
7.8
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19807)

CVE-2023-30647
Samsung Mobile Devices General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

Heap out of bound write vulnerability in IpcRxUsimPhoneBookCapa of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

CVE-2023-51557
PDF Reader General
7.8
HIGH
EPSS
1.6%
2023 CWE-416 1 PoC

Foxit PDF Reader AcroForm Doc Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current

CVE-2023-20224
Cisco ThousandEyes Recorder Application Networking
7.8
HIGH
EPSS
0.0%
2023 CWE-284 2 PoCs

A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient input validation of user-supplied CLI arguments. An attacker could exploit this vulnerability by authenticating to an affected device and using crafted commands at the prompt. A successful exploit could allow the attacker to execute arbitrary commands as root. The attacker must have valid credentials on the affected device.

CVE-2023-1829
Linux Kernel General
7.8
HIGH
EPSS
0.3%
2023 CWE-416 2 PoCs

A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting the underlying structure which can later lead to double freeing the structure. A local attacker user can use this vulnerability to elevate its privileges to root. We recommend upgrading past commit 8c710f75256bb3cf05ac7b1672c82b92c43f3d28.

CVE-2023-29742
Software Genérico General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a code execution attack by manipulating the database.

CVE-2023-30645
Samsung Mobile Devices General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

Heap out of bound write vulnerability in IpcRxIncomingCBMsg of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

CVE-2023-21773
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
2.0%
2023 CWE-416 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-51556
PDF Reader General
7.8
HIGH
EPSS
1.7%
2023 CWE-416 1 PoC

Foxit PDF Reader AcroForm Doc Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current

CVE-2023-25428
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 1 PoC

A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leading to code execution.

CVE-2023-40140
Android General
7.8
HIGH
EPSS
0.1%
2023 2 PoCs

In android_view_InputDevice_create of android_view_InputDevice.cpp, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-51551
PDF Reader General
7.8
HIGH
EPSS
1.6%
2023 CWE-416 1 PoC

Foxit PDF Reader AcroForm Signature Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Signature objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of

CVE-2023-35788
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 2 PoCs

An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.

CVE-2023-20943
Android General
7.8
HIGH
EPSS
0.0%
2023 2 PoCs

In clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-240267890

CVE-2023-27193
Software Genérico General
7.8
HIGH
EPSS
0.2%
2023 1 PoC

An issue found in DUALSPACE v.1.1.3 allows a local attacker to gain privileges via the key_ad_new_user_avoid_time field.