7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-5427
Bifrost GPU Kernel Driver General
7.8
HIGH
EPSS
0.1%
2023 CWE-416 2 PoCs

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r44p0 through r45p0; Valhall GPU Kernel Driver: from r44p0 through r45p0; Arm 5th Gen GPU Architecture Kernel Driver: from r44p0 through r45p0.

CVE-2023-21746
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
53.7%
2023 1 PoC

Windows NTLM Elevation of Privilege Vulnerability

CVE-2023-21675
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
1.0%
2023 CWE-843 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-27329
PDF Reader General
7.8
HIGH
EPSS
3.5%
2023 CWE-416 1 PoC

Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the cu

CVE-2023-1665
linagora/twake General
7.8
HIGH
EPSS
0.2%
2023 CWE-307 2 PoCs

Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 0.0.0.

CVE-2023-27193
Software Genérico General
7.8
HIGH
EPSS
0.2%
2023 1 PoC

An issue found in DUALSPACE v.1.1.3 allows a local attacker to gain privileges via the key_ad_new_user_avoid_time field.

CVE-2023-29738
Software Genérico General
7.8
HIGH
EPSS
0.2%
2023 2 PoCs

An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause code execution and escalation of Privileges via the database files.

CVE-2023-31248
Linux Kernel General
7.8
HIGH
EPSS
0.2%
2023 CWE-416 2 PoCs

Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace

CVE-2023-1078
Linux kernel General
7.8
HIGH
EPSS
0.0%
2023 CWE-787 1 PoC

A flaw was found in the Linux Kernel in RDS (Reliable Datagram Sockets) protocol. The rds_rm_zerocopy_callback() uses list_entry() on the head of a list causing a type confusion. Local user can trigger this with rds_message_put(). Type confusion leads to `struct rds_msg_zcopy_info *info` actually points to something else that is potentially controlled by local user. It is known how to trigger this, which causes an out of bounds access, and a lock corruption.

CVE-2023-32837
MT6883, MT6885, MT6889, MT6893, MT8797, MT8798 General
7.8
HIGH
EPSS
0.0%
2023 1 PoC

In video, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08235273; Issue ID: ALPS08250357.

CVE-2023-4208
Kernel General
7.8
HIGH
EPSS
0.0%
2023 CWE-416 1 PoC

A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. When u32_change() is called on an existing filter, the whole tcf_result struct is always copied into the new instance of the filter. This causes a problem when updating a filter bound to a class, as tcf_unbind_filter() is always called on the old instance in the success path, decreasing filter_cnt of the still referenced class and allowing it to be deleted, leading to a use-after-free. We recommend upgrading past commit 3044b16e7c6fe5d24b1cdbcf1bd0a9d92d1e

CVE-2023-3812
Red Hat Enterprise Linux 8 Web
7.8
HIGH
EPSS
0.0%
2023 CWE-787 1 PoC

An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVE-2023-21109
Android General
7.8
HIGH
EPSS
0.0%
2023 1 PoC

In multiple places of AccessibilityService, there is a possible way to hide the app from the user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-261589597

CVE-2023-25365
Software Genérico Web
7.8
HIGH
EPSS
0.0%
2023 1 PoC

Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3

CVE-2023-31017
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
7.8
HIGH
EPSS
0.0%
2023 CWE-552 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may be able to write arbitrary data to privileged locations by using reparse points. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

CVE-2023-51560
PDF Reader General
7.8
HIGH
EPSS
1.5%
2023 CWE-843 1 PoC

Foxit PDF Reader Annotation Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of t

CVE-2023-21772
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
2.0%
2023 CWE-125 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-23421
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
1.0%
2023 CWE-416 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-31436
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 4 PoCs

qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX.

CVE-2023-32183
Tumbleweed General
7.8
HIGH
EPSS
0.1%
2023 CWE-276 1 PoC

Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hacluster to escalate to root This issue affects openSUSE Tumbleweed.