7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-1521
sccache Web
7.8
HIGH
EPSS
0.3%
2023 CWE-426 2 PoCs

On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library passed to LD_PRELOAD. If the server is run as root (which is the default when installing the snap package https://snapcraft.io/sccache ), this means a user running the sccache client can get root privileges.

CVE-2023-0860
modoboa/modoboa-installer General
7.8
HIGH
EPSS
0.5%
2023 CWE-307 2 PoCs

Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4.

CVE-2023-1078
Linux kernel General
7.8
HIGH
EPSS
0.0%
2023 CWE-787 1 PoC

A flaw was found in the Linux Kernel in RDS (Reliable Datagram Sockets) protocol. The rds_rm_zerocopy_callback() uses list_entry() on the head of a list causing a type confusion. Local user can trigger this with rds_message_put(). Type confusion leads to `struct rds_msg_zcopy_info *info` actually points to something else that is potentially controlled by local user. It is known how to trigger this, which causes an out of bounds access, and a lock corruption.

CVE-2023-50008
Software Genérico Networking
7.8
HIGH
EPSS
0.0%
2023 1 PoC

FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrect filter, in the av_malloc function in libavutil/mem.c:105:9 component.

CVE-2023-27390
Diagon General
7.8
HIGH
EPSS
0.1%
2023 CWE-122 2 PoCs

A heap-based buffer overflow vulnerability exists in the Sequence::DrawText functionality of Diagon v1.0.139. A specially crafted markdown file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

CVE-2023-44372
Acrobat Reader General
7.8
HIGH
EPSS
0.7%
2023 CWE-416 1 PoC

Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2023-38141
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.3%
2023 CWE-367 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-37418
GTKWave General
7.8
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the vcd2vzt conversion utility.

CVE-2023-38118
PDF Reader General
7.8
HIGH
EPSS
2.1%
2023 CWE-787 1 PoC

Foxit PDF Reader AcroForm Doc Object Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute

CVE-2023-20933
Android General
7.8
HIGH
EPSS
0.0%
2023 2 PoCs

In several functions of MediaCodec.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-245860753

CVE-2023-23423
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
1.1%
2023 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-33137
Microsoft Office 2019 General
7.8
HIGH
EPSS
2.7%
2023 CWE-415 1 PoC

Microsoft Excel Remote Code Execution Vulnerability

CVE-2023-36887
Microsoft Edge (Chromium-based) General
7.8
HIGH
EPSS
1.3%
2023 1 PoC

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVE-2023-34319
Linux General
7.8
HIGH
EPSS
0.0%
2023 1 PoC

The fix for XSA-423 added logic to Linux'es netback driver to deal with a frontend splitting a packet in a way such that not all of the headers would come in one piece. Unfortunately the logic introduced there didn't account for the extreme case of the entire packet being split into as many pieces as permitted by the protocol, yet still being smaller than the area that's specially dealt with to keep all (possible) headers together. Such an unusual packet would therefore trigger a buffer overrun in the driver.

CVE-2023-38107
PDF Reader General
7.8
HIGH
EPSS
1.8%
2023 CWE-416 1 PoC

Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the cu

CVE-2023-3313
Enterprise Security Manager Web
7.8
HIGH
EPSS
0.2%
2023 CWE-78 1 PoC

An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed an unauthorized user to execute system command injection for the purpose of privilege escalation or to execute arbitrary commands.

CVE-2023-51560
PDF Reader General
7.8
HIGH
EPSS
1.5%
2023 CWE-843 1 PoC

Foxit PDF Reader Annotation Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of t

CVE-2023-31017
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
7.8
HIGH
EPSS
0.0%
2023 CWE-552 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may be able to write arbitrary data to privileged locations by using reparse points. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

CVE-2023-6179
ProWatch General
7.8
HIGH
EPSS
0.0%
2023 CWE-732 1 PoC

Honeywell ProWatch, 4.5, including all Service Pack versions, contain a Vulnerability in Application Server's executable folder(s). A(n) attacker could potentially exploit this vulnerability, leading to a standard user to have arbitrary system code execution. Honeywell recommends updating to the most recent version of this product, service or offering (Pro-watch 6.0.2, 6.0, 5.5.2,5.0.5).