5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-51560
PDF Reader General
7.8
HIGH
EPSS
1.5%
2023 CWE-843 1 PoC

Foxit PDF Reader Annotation Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of t

CVE-2023-3390
Linux Kernel Web
7.8
HIGH
EPSS
0.1%
2023 CWE-416 2 PoCs

A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a dangling pointer in the same transaction causing a use-after-free vulnerability. This flaw allows a local attacker with user access to cause a privilege escalation issue. We recommend upgrading past commit 1240eb93f0616b21c675416516ff3d74798fdc97.

CVE-2023-20928
Android General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

In binder_vma_close of binder.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-254837884References: Upstream kernel

CVE-2023-31436
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 4 PoCs

qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX.

CVE-2023-27330
PDF Reader General
7.8
HIGH
EPSS
3.5%
2023 CWE-416 1 PoC

Foxit PDF Reader XFA Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of th

CVE-2023-1676
DriverGenius General
7.8
HIGH
EPSS
0.1%
2023 CWE-119 2 PoCs

A vulnerability was found in DriverGenius 9.70.0.346. It has been declared as critical. Affected by this vulnerability is the function 0x9C402088 in the library mydrivers64.sys of the component IOCTL Handler. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The identifier VDB-224233 was assigned to this vulnerability.

CVE-2023-4751
vim/vim General
7.8
HIGH
EPSS
0.0%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.

CVE-2023-39444
GTKWave General
7.8
HIGH
EPSS
0.1%
2023 CWE-119 2 PoCs

Multiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write perfomed by the string copy loop.

CVE-2023-7016
SafeNet Authentication Client Windows
7.8
HIGH
EPSS
0.1%
2023 CWE-269 1 PoC

A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access.

CVE-2023-38128
Ichitaro 2023 General
7.8
HIGH
EPSS
0.2%
2023 CWE-843 2 PoCs

An out-of-bounds write vulnerability exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause a type confusion, which can lead to memory corruption and eventually arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-4206
Kernel General
7.8
HIGH
EPSS
0.1%
2023 CWE-416 1 PoC

A use-after-free vulnerability in the Linux kernel's net/sched: cls_route component can be exploited to achieve local privilege escalation. When route4_change() is called on an existing filter, the whole tcf_result struct is always copied into the new instance of the filter. This causes a problem when updating a filter bound to a class, as tcf_unbind_filter() is always called on the old instance in the success path, decreasing filter_cnt of the still referenced class and allowing it to be deleted, leading to a use-after-free. We recommend upgrading past commit b80b829e9e2c1b3f7aae34855e04d8f

CVE-2023-20224
Cisco ThousandEyes Recorder Application Networking
7.8
HIGH
EPSS
0.0%
2023 CWE-284 2 PoCs

A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient input validation of user-supplied CLI arguments. An attacker could exploit this vulnerability by authenticating to an affected device and using crafted commands at the prompt. A successful exploit could allow the attacker to execute arbitrary commands as root. The attacker must have valid credentials on the affected device.

CVE-2023-39374
NAC SecureConnector General
7.8
HIGH
EPSS
0.1%
2023 CWE-427 1 PoC

ForeScout NAC SecureConnector version 11.2 - CWE-427: Uncontrolled Search Path Element

CVE-2023-36424
🔥 KEV Windows 11 version 22H3 Windows
7.8
HIGH
EPSS
8.0%
2023 CWE-125 2 PoCs

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2023-30644
Samsung Mobile Devices General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

Stack out of bound write vulnerability in CdmaSmsParser of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

CVE-2023-27651
Software Genérico General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges via the update_info field of the _default_.xml file.

CVE-2023-32495
PowerScale OneFS General
7.8
HIGH
EPSS
0.1%
2023 CWE-200 1 PoC

Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized Actor vulnerability. An authorized local attacker could potentially exploit this vulnerability, leading to escalation of privileges.

CVE-2023-20933
Android General
7.8
HIGH
EPSS
0.0%
2023 2 PoCs

In several functions of MediaCodec.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-245860753

CVE-2023-27402
Tecnomatix Plant Simulation General
7.8
HIGH
EPSS
0.1%
2023 CWE-125 1 PoC

A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted SPP files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-20334)

CVE-2023-5717
Kernel General
7.8
HIGH
EPSS
0.3%
2023 CWE-787 1 PoC

A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation. If perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can increment or write to memory locations outside of the allocated buffer. We recommend upgrading past commit 32671e3799ca2e4590773fd0e63aaa4229e50c06.