5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-40130
Android General
7.8
HIGH
EPSS
0.0%
2023 1 PoC

In notifyTimeout of CallRedirectionProcessor, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege and background activity launch with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-43250
Software Genérico General
7.8
HIGH
EPSS
0.2%
2023 2 PoCs

XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow. There is a User Mode Write AV via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

CVE-2023-4911
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
71.5%
2023 CWE-122 22 PoCs

A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.

CVE-2023-33240
Software Genérico Windows
7.8
HIGH
EPSS
0.1%
2023 1 PoC

Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53785 and all previous 11.x versions, and 10.1.11.37866 and earlier) on Windows allows Local Privilege Escalation when installed to a non-default directory because unprivileged users have access to an executable file of a system service. This is fixed in 12.1.2.

CVE-2023-35382
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
2.0%
2023 CWE-416 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-31102
Software Genérico General
7.8
HIGH
EPSS
50.7%
2023 1 PoC

Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.

CVE-2023-0433
vim/vim General
7.8
HIGH
EPSS
0.0%
2023 CWE-122 2 PoCs

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.

CVE-2023-26127
n158 General
7.8
HIGH
EPSS
0.1%
2023 CWE-78 1 PoC

All versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports' function. **Note:** To execute the code snippet and potentially exploit the vulnerability, the attacker needs to have the ability to run Node.js code within the target environment. This typically requires some level of access to the system or application hosting the Node.js environment.

CVE-2023-31468
Software Genérico General
7.8
HIGH
EPSS
0.1%
2023 4 PoCs

An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\INOSOFT GmbH" folder has weak permissions for Everyone, allowing an attacker to insert a Trojan horse file that runs as SYSTEM. 2024-1 is a fixed version.

CVE-2023-24992
Tecnomatix Plant Simulation General
7.8
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19814)

CVE-2023-24993
Tecnomatix Plant Simulation General
7.8
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19815)

CVE-2023-0247
bits-and-blooms/bloom General
7.8
HIGH
EPSS
0.1%
2023 CWE-427 1 PoC

Uncontrolled Search Path Element in GitHub repository bits-and-blooms/bloom prior to 3.3.1.

CVE-2023-0770
gpac/gpac General
7.8
HIGH
EPSS
0.0%
2023 CWE-121 1 PoC

Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.

CVE-2023-51791
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 2 PoCs

Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavcodec/jpegxl_parser.c in gen_alias_map.

CVE-2023-38141
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.3%
2023 CWE-367 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-29724
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 1 PoC

The BT21 x BTS Wallpaper app 12 for Android allows unauthorized apps to actively request permission to modify data in the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the app is opened. An attacker could tamper with this data to cause an escalation of privilege attack.

CVE-2023-33148
Microsoft Office 2013 Click-to-Run (C2R) General
7.8
HIGH
EPSS
1.7%
2023 CWE-59 1 PoC

Microsoft Office Elevation of Privilege Vulnerability

CVE-2023-39063
Software Genérico General
7.8
HIGH
EPSS
1.5%
2023 1 PoC

Buffer Overflow vulnerability in RaidenFTPD 2.4.4005 allows a local attacker to execute arbitrary code via the Server name field of the Step by step setup wizard.

CVE-2023-39444
GTKWave General
7.8
HIGH
EPSS
0.1%
2023 CWE-119 2 PoCs

Multiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write perfomed by the string copy loop.