5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-4207
Kernel General
7.8
HIGH
EPSS
0.0%
2023 CWE-416 2 PoCs

A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privilege escalation. When fw_change() is called on an existing filter, the whole tcf_result struct is always copied into the new instance of the filter. This causes a problem when updating a filter bound to a class, as tcf_unbind_filter() is always called on the old instance in the success path, decreasing filter_cnt of the still referenced class and allowing it to be deleted, leading to a use-after-free. We recommend upgrading past commit 76e42ae831991c828cffa8c37736ebfb831ad5

CVE-2023-29752
Software Genérico General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

An issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the component.

CVE-2023-31287
Software Genérico General
7.8
HIGH
EPSS
0.1%
2023 2 PoCs

An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. Password reset links are sent by email. A link contains a token that is used to reset the password. This token remains valid even after the password reset and can be used a second time to change the password of the corresponding user. The token expires only 3 hours after issuance and is sent as a query parameter when resetting. An attacker with access to the browser history can thus use the token again to change the password in order to take over the account.

CVE-2023-0950
LibreOffice General
7.8
HIGH
EPSS
0.1%
2023 CWE-129 1 PoC

Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when loaded. In the affected versions of LibreOffice certain malformed spreadsheet formulas, such as AGGREGATE, could be created with less parameters passed to the formula interpreter than it expected, leading to an array index underflow, in which case there is a risk that arbitrary code could be executed. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.6

CVE-2023-1900
Avira Antivirus General
7.8
HIGH
EPSS
0.1%
2023 CWE-190 1 PoC

A vulnerability within the Avira network protection feature allowed an attacker with local execution rights to cause an overflow. This could corrupt the data on the heap and lead to a denial-of-service situation. Issue was fixed with Endpointprotection.exe version 1.0.2303.633

CVE-2023-49113
SAST Local Analyzer General
7.8
HIGH
EPSS
0.0%
2023 CWE-312 3 PoCs

The Kiuwan Local Analyzer (KLA) Java scanning application contains several hard-coded secrets in plain text format. In some cases, this can potentially compromise the confidentiality of the scan results. Several credentials were found in the JAR files of the Kiuwan Local Analyzer. The JAR file "lib.engine/insight/optimyth-insight.jar" contains the file "InsightServicesConfig.properties", which has the configuration tokens "insight.github.user" as well as "insight.github.password" prefilled with credentials. At least the specified username corresponds to a valid GitHub account. The JAR

CVE-2023-27401
Tecnomatix Plant Simulation General
7.8
HIGH
EPSS
0.1%
2023 CWE-125 1 PoC

A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted SPP files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-20308, ZDI-CAN-20345)

CVE-2023-21608
🔥 KEV Acrobat Reader General
7.8
HIGH
EPSS
77.5%
2023 CWE-416 3 PoCs

Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2023-29755
Software Genérico General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

An issue found in Twilight v.13.3 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files.

CVE-2023-4752
vim/vim General
7.8
HIGH
EPSS
0.1%
2023 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.1858.

CVE-2023-21086
Android General
7.8
HIGH
EPSS
0.0%
2023 1 PoC

In isToggleable of SecureNfcEnabler.java and SecureNfcPreferenceController.java, there is a possible way to enable NFC from a secondary account due to a permissions bypass. This could lead to local escalation of privilege from the Guest account with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-238298970

CVE-2023-5535
vim/vim General
7.8
HIGH
EPSS
0.0%
2023 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to v9.0.2010.

CVE-2023-38118
PDF Reader General
7.8
HIGH
EPSS
2.1%
2023 CWE-787 1 PoC

Foxit PDF Reader AcroForm Doc Object Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute

CVE-2023-24986
Tecnomatix Plant Simulation General
7.8
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19808)

CVE-2023-30237
Software Genérico Networking Windows
7.8
HIGH
EPSS
0.0%
2023 2 PoCs

CyberGhostVPN Windows Client before v8.3.10.10015 was discovered to contain a DLL injection vulnerability via the component Dashboard.exe.

CVE-2023-36424
🔥 KEV Windows 11 version 22H3 Windows
7.8
HIGH
EPSS
8.0%
2023 CWE-125 2 PoCs

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2023-5197
Kernel General
7.8
HIGH
EPSS
0.1%
2023 CWE-416 1 PoC

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Addition and removal of rules from chain bindings within the same transaction causes leads to use-after-free. We recommend upgrading past commit f15f29fd4779be8a418b66e9d52979bb6d6c2325.

CVE-2023-2640
Ubuntu Kernel General
7.8
HIGH
EPSS
91.4%
2023 CWE-863 9 PoCs

On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.

CVE-2023-43907
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 1 PoC

OptiPNG v0.7.7 was discovered to contain a global buffer overflow via the 'buffer' variable at gifread.c.