7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-42091
PDF Reader General
7.8
HIGH
EPSS
1.9%
2023 CWE-416 1 PoC

Foxit PDF Reader XFA Doc Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the curre

CVE-2023-20937
Android General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

In several functions of the Android Linux kernel, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-257443051References: Upstream kernel

CVE-2023-21433
Galaxy Store General
7.8
HIGH
EPSS
2.8%
2023 CWE-285 1 PoC

Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applications from Galaxy Store.

CVE-2023-24579
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 1 PoC

McAfee Total Protection prior to 16.0.51 allows attackers to trick a victim into uninstalling the application via the command prompt.

CVE-2023-41992
🔥 KEV macOS General
7.8
HIGH
EPSS
1.1%
2023 1 PoC

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CVE-2023-41064
🔥 KEV macOS General
7.8
HIGH
EPSS
85.4%
2023 6 PoCs

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 and iPadOS 15.7.9, macOS Big Sur 11.7.10. Processing a maliciously crafted image may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVE-2023-29749
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 1 PoC

An issue found in Yandex Navigator v.6.60 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files.

CVE-2023-38118
PDF Reader General
7.8
HIGH
EPSS
2.1%
2023 CWE-787 1 PoC

Foxit PDF Reader AcroForm Doc Object Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute

CVE-2023-29766
Software Genérico General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

An issue found in CrossX v.1.15.3 for Android allows a local attacker to cause an escalation of Privileges via the database files.

CVE-2023-23514
macOS General
7.8
HIGH
EPSS
0.4%
2023 2 PoCs

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, macOS Big Sur 11.7.5. An app may be able to execute arbitrary code with kernel privileges.

CVE-2023-4734
vim/vim General
7.8
HIGH
EPSS
0.0%
2023 CWE-190 1 PoC

Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.

CVE-2023-4622
Kernel General
7.8
HIGH
EPSS
0.0%
2023 CWE-416 3 PoCs

A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without locking the queue. Thus there is a race where unix_stream_sendpage() could access an skb locklessly that is being released by garbage collection, resulting in use-after-free. We recommend upgrading past commit 790c2f9d15b594350ae9bca7b236f2b1859de02c.

CVE-2023-21747
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.4%
2023 CWE-416 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-31019
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
7.8
HIGH
EPSS
0.0%
2023 CWE-284 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrectly restricts access from the named pipe server to a connecting client, which may lead to potential impersonation to the client's secure context.

CVE-2023-37418
GTKWave General
7.8
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the vcd2vzt conversion utility.

CVE-2023-5345
Kernel Windows
7.8
HIGH
EPSS
0.0%
2023 CWE-416 1 PoC

A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation. In case of an error in smb3_fs_context_parse_param, ctx->password was freed but the field was not set to NULL which could lead to double free. We recommend upgrading past commit e6e43b8aa7cd3c3af686caf0c2e11819a886d705.

CVE-2023-6931
Kernel General
7.8
HIGH
EPSS
0.2%
2023 CWE-787 3 PoCs

A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_group(). We recommend upgrading past commit 382c27f4ed28f803b1f1473ac2d8db0afc795a1b.

CVE-2023-20871
VMware Fusion General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate privileges to gain root access to the host operating system.

CVE-2023-3889
Valhall GPU Kernel Driver General
7.8
HIGH
EPSS
0.1%
2023 CWE-119 1 PoC

A local non-privileged user can make improper GPU memory processing operations. If the operations are carefully prepared, then they could be used to gain access to already freed memory.

CVE-2023-21987
VM VirtualBox Database
7.8
HIGH
EPSS
9.7%
2023 2 PoCs

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, In