2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-21477
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.0%
2023 1 PoC

Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.

CVE-2023-4876
hamza417/inure General
7.9
HIGH
EPSS
0.1%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository hamza417/inure prior to build92.

CVE-2023-40283
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 2 PoCs

An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled.

CVE-2023-1829
Linux Kernel General
7.8
HIGH
EPSS
0.3%
2023 CWE-416 2 PoCs

A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting the underlying structure which can later lead to double freeing the structure. A local attacker user can use this vulnerability to elevate its privileges to root. We recommend upgrading past commit 8c710f75256bb3cf05ac7b1672c82b92c43f3d28.

CVE-2023-51557
PDF Reader General
7.8
HIGH
EPSS
1.6%
2023 CWE-416 1 PoC

Foxit PDF Reader AcroForm Doc Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current

CVE-2023-44372
Acrobat Reader General
7.8
HIGH
EPSS
0.7%
2023 CWE-416 1 PoC

Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2023-38127
Ichitaro 2023 General
7.8
HIGH
EPSS
0.2%
2023 CWE-190 2 PoCs

An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause the parser to make an under-sized allocation, which can later allow for memory corruption, potentially resulting in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-21749
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
1.5%
2023 CWE-20 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-4622
Kernel General
7.8
HIGH
EPSS
0.0%
2023 CWE-416 3 PoCs

A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without locking the queue. Thus there is a race where unix_stream_sendpage() could access an skb locklessly that is being released by garbage collection, resulting in use-after-free. We recommend upgrading past commit 790c2f9d15b594350ae9bca7b236f2b1859de02c.

CVE-2023-22023
Solaris Operating System Database
7.8
HIGH
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Interface). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. Note: CVE-2023-22023 is equivalent to CVE-2023-31284. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVE-2023-45898
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 2 PoCs

The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.

CVE-2023-51794
Software Genérico General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/af_stereowiden.c:120:69.

CVE-2023-21747
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.4%
2023 CWE-416 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-24068
Software Genérico Windows
7.8
HIGH
EPSS
0.1%
2023 1 PoC

Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to modify conversation attachments within the attachments.noindex directory. Client mechanisms fail to validate modifications of existing cached files, resulting in an attacker's ability to insert malicious code into pre-existing attachments or replace them completely. A threat actor can forward the existing attachment in the corresponding conversation to external groups, and the name and size of the file will not change, allowing the malware to masquerade as another file. NOTE: the vendor disputes the relevance of thi

CVE-2023-27193
Software Genérico General
7.8
HIGH
EPSS
0.2%
2023 1 PoC

An issue found in DUALSPACE v.1.1.3 allows a local attacker to gain privileges via the key_ad_new_user_avoid_time field.

CVE-2023-29738
Software Genérico General
7.8
HIGH
EPSS
0.2%
2023 2 PoCs

An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause code execution and escalation of Privileges via the database files.

CVE-2023-25428
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 1 PoC

A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leading to code execution.

CVE-2023-30645
Samsung Mobile Devices General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

Heap out of bound write vulnerability in IpcRxIncomingCBMsg of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

CVE-2023-35788
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 2 PoCs

An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.

CVE-2023-51551
PDF Reader General
7.8
HIGH
EPSS
1.6%
2023 CWE-416 1 PoC

Foxit PDF Reader AcroForm Signature Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Signature objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of