Total
22706 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-23507 | 1 Apple | 1 Macos | 2023-03-03 | N/A | 7.8 HIGH |
The issue was addressed with improved bounds checks. This issue is fixed in macOS Ventura 13.2, macOS Monterey 12.6.3. An app may be able to execute arbitrary code with kernel privileges. | |||||
CVE-2019-3629 | 1 Mcafee | 1 Enterprise Security Manager | 2023-03-03 | 4.3 MEDIUM | 6.5 MEDIUM |
Application protection bypass vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows unauthenticated user to impersonate system users via specially crafted parameters. | |||||
CVE-2019-11884 | 6 Canonical, Debian, Fedoraproject and 3 more | 12 Ubuntu Linux, Debian Linux, Fedora and 9 more | 2023-03-03 | 2.1 LOW | 3.3 LOW |
The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character. | |||||
CVE-2019-3628 | 1 Mcafee | 1 Enterprise Security Manager | 2023-03-03 | 6.5 MEDIUM | 8.8 HIGH |
Privilege escalation in McAfee Enterprise Security Manager (ESM) 11.x prior to 11.2.0 allows authenticated user to gain access to a core system component via incorrect access control. | |||||
CVE-2022-36231 | 1 Newspaperclub | 1 Pdf Info | 2023-03-03 | N/A | 9.8 CRITICAL |
pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3. | |||||
CVE-2019-14416 | 1 Veritas | 1 Resiliency Platform | 2023-03-03 | 9.0 HIGH | 7.2 HIGH |
An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. An arbitrary command execution vulnerability allows a malicious VRP user to execute commands with root privilege within the VRP virtual machine, related to resiliency plans and custom script functionality. | |||||
CVE-2018-6678 | 1 Mcafee | 1 Mcafee Web Gateway | 2023-03-03 | 6.5 MEDIUM | 9.1 CRITICAL |
Configuration/Environment manipulation vulnerability in the administrative interface in McAfee Web Gateway (MWG) MWG 7.8.1.x allows authenticated administrator users to execute arbitrary commands via unspecified vectors. | |||||
CVE-2019-3742 | 1 Dell | 1 Digital Delivery | 2023-03-03 | 7.2 HIGH | 7.8 HIGH |
Dell/Alienware Digital Delivery versions prior to 3.5.2013 contain a privilege escalation vulnerability. A local non-privileged malicious user could exploit a named pipe that performs binary deserialization via a process hollowing technique to inject malicous code to run an executable with elevated privileges. | |||||
CVE-2019-1020017 | 1 Discourse | 1 Discourse | 2023-03-03 | 5.0 MEDIUM | 5.3 MEDIUM |
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP. | |||||
CVE-2023-26468 | 1 Cerebrate-project | 1 Cerebrate | 2023-03-03 | N/A | 9.1 CRITICAL |
Cerebrate 1.12 does not properly consider organisation_id during creation of API keys. | |||||
CVE-2023-25621 | 1 Apache | 1 Sling I18n | 2023-03-03 | N/A | 6.5 MEDIUM |
Privilege Escalation vulnerability in Apache Software Foundation Apache Sling. Any content author is able to create i18n dictionaries in the repository in a location the author has write access to. As these translations are used across the whole product, it allows an author to change any text or dialog in the product. For example an attacker might fool someone by changing the text on a delete button to "Info". This issue affects the i18n module of Apache Sling up to version 2.5.18. Version 2.6.2 and higher limit by default i18m dictionaries to certain paths in the repository (/libs and /apps). Users of the module are advised to update to version 2.6.2 or higher, check the configuration for resource loading and then adjust the access permissions for the configured path accordingly. | |||||
CVE-2023-22476 | 1 Mantisbt | 1 Mantisbt | 2023-03-03 | N/A | 4.3 MEDIUM |
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions prior to 2.25.6, due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can access to the _Summary_ field of private Issues (i.e. having Private view status, or belonging to a private Project) via a crafted `bug_arr[]` parameter in *bug_actiongroup_ext.php*. This issue is fixed in version 2.25.6. There are no workarounds. | |||||
CVE-2022-32189 | 1 Golang | 1 Go | 2023-03-03 | N/A | 7.5 HIGH |
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service. | |||||
CVE-2019-16910 | 3 Arm, Debian, Fedoraproject | 4 Mbed Crypto, Mbed Tls, Debian Linux and 1 more | 2023-03-03 | 2.6 LOW | 5.3 MEDIUM |
Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks if a victim signs the same message many times. (For Mbed TLS, the fix is also available in versions 2.7.12 and 2.16.3.) | |||||
CVE-2021-36690 | 3 Apple, Oracle, Sqlite | 6 Iphone Os, Macos, Tvos and 3 more | 2023-03-03 | 5.0 MEDIUM | 7.5 HIGH |
** DISPUTED ** A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute commands). This report does NOT imply any problem in the SQLite library. | |||||
CVE-2020-25736 | 1 Acronis | 1 True Image | 2023-03-03 | 4.6 MEDIUM | 7.8 HIGH |
Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service configuration. | |||||
CVE-2021-33587 | 2 Css-what Project, Netapp | 2 Css-what, E-series Performance Analyzer | 2023-03-03 | 5.0 MEDIUM | 7.5 HIGH |
The css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity relative to the size of the input. | |||||
CVE-2023-22953 | 1 Expressionengine | 1 Expressionengine | 2023-03-03 | N/A | 8.8 HIGH |
In ExpressionEngine before 7.2.6, remote code execution can be achieved by an authenticated Control Panel user. | |||||
CVE-2019-14441 | 1 Libav | 1 Libav | 2023-03-02 | 4.3 MEDIUM | 6.5 MEDIUM |
** DISPUTED ** An issue was discovered in Libav 12.3. An access violation allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv. This is related to ff_mpa_synth_filter_float in avcodec/mpegaudiodsp_template.c. NOTE: This may be a duplicate of CVE-2018-19129. | |||||
CVE-2023-24114 | 1 Typecho | 1 Typecho | 2023-03-02 | N/A | 9.8 CRITICAL |
typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php. |