CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2023-46764

    Last Modified: 21 Nov 2024

    Unauthorized startup vulnerability of background apps. Successful exploitation of this vulnerability may cause background apps to start maliciously.

    Published: 8 Nov 2023
    5.3
    Medium

    CVE-2023-46763

    Last Modified: 21 Nov 2024

    Vulnerability of background app permission management in the framework module. Successful exploitation of this vulnerability may cause background apps to start maliciously.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-46762

    Last Modified: 21 Nov 2024

    Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-46761

    Last Modified: 21 Nov 2024

    Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-46760

    Last Modified: 21 Nov 2024

    Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-46767

    Last Modified: 21 Nov 2024

    Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-46766

    Last Modified: 21 Nov 2024

    Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-46765

    Last Modified: 21 Nov 2024

    Vulnerability of uncaught exceptions in the NFC module. Successful exploitation of this vulnerability can affect NFC availability.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-46774

    Last Modified: 21 Nov 2024

    Vulnerability of uncaught exceptions in the NFC module. Successful exploitation of this vulnerability can affect NFC availability.

    Published: 8 Nov 2023
    5.9
    Medium

    CVE-2022-48613

    Last Modified: 21 Nov 2024

    Race condition vulnerability in the kernel module. Successful exploitation of this vulnerability may cause variable values to be read with the condition evaluation bypassed.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-46772

    Last Modified: 21 Nov 2024

    Vulnerability of parameters being out of the value range in the QMI service module. Successful exploitation of this vulnerability may cause errors in reading file data.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-46771

    Last Modified: 21 Nov 2024

    Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-44098

    Last Modified: 21 Nov 2024

    Vulnerability of missing encryption in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-5978

    Last Modified: 13 Feb 2025

    In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstances the cap_net libcasper(3) service incorrectly validates that updated constraints are strictly subsets of the active constraints.  When only a list of resolvable domain names was specified without setting any other limitations, an application could submit a new list of domains including include entries not previously listed.  This could permit the application to resolve domain names that were previously restricted.

    Published: 8 Nov 2023
    9.8
    Critical

    CVE-2023-5941

    Last Modified: 13 Feb 2025

    In versions of FreeBSD 12.4-RELEASE prior to 12.4-RELEASE-p7 and FreeBSD 13.2-RELEASE prior to 13.2-RELEASE-p5 the __sflush() stdio function in libc does not correctly update FILE objects' write space members for write-buffered streams when the write(2) system call returns an error.  Depending on the nature of an application that calls libc's stdio functions and the presence of errors returned from the write(2) system call (or an overridden stdio write routine) a heap buffer overflow may occur. Such overflows may lead to data corruption or the execution of arbitrary code at the privilege level of the calling program.

    Published: 8 Nov 2023
    3.5
    Low

    CVE-2023-41270

    Last Modified: 21 Nov 2024

    Improper Restriction of Excessive Authentication Attempts vulnerability in Samsung Smart TV UE40D7000 version T-GAPDEUC-1033.2 and before allows attackers to cause a denial of service via WPS attack tools.

    Published: 8 Nov 2023
    —
    Unknown

    CVE-2023-6010

    Last Modified: 14 Nov 2023

    Accidental Request.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-44115

    Last Modified: 21 Nov 2024

    Vulnerability of improper permission control in the Booster module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-46770

    Last Modified: 21 Nov 2024

    Out-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may cause mistouch prevention errors on users' mobile phones.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-46769

    Last Modified: 21 Nov 2024

    Use-After-Free (UAF) vulnerability in the dubai module. Successful exploitation of this vulnerability will affect availability.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-46768

    Last Modified: 21 Nov 2024

    Multi-thread vulnerability in the idmap module. Successful exploitation of this vulnerability may cause features to perform abnormally.

    Published: 8 Nov 2023
    9.1
    Critical

    CVE-2023-5801

    Last Modified: 21 Nov 2024

    Vulnerability of identity verification being bypassed in the face unlock module. Successful exploitation of this vulnerability will affect integrity and confidentiality.

    Published: 8 Nov 2023
    9.9
    Critical

    CVE-2021-43609

    Last Modified: 21 Nov 2024

    An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket function in app/models/reporting/database_query.rb allows an authenticated attacker to execute arbitrary SQL commands via the sort parameter. This can be leveraged to leak local files from the host system, leading to remote code execution (RCE) through deserialization of malicious data.

    Published: 8 Nov 2023
    5.4
    Medium

    CVE-2023-46483

    Last Modified: 21 Nov 2024

    Cross Site Scripting vulnerability in timetec AWDMS v.2.0 allows an attacker to obtain sensitive information via a crafted payload to the remark parameter of the New Zone function.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-36667

    Last Modified: 21 Nov 2024

    Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal.

    Published: 8 Nov 2023
    9.8
    Critical

    CVE-2023-29974

    Last Modified: 21 Nov 2024

    An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.

    Published: 8 Nov 2023
    5.4
    Medium

    CVE-2023-37790

    Last Modified: 21 Nov 2024

    Jaspersoft Clarity PPM version 14.3.0.298 was discovered to contain an arbitrary file upload vulnerability via the Profile Picture Upload function.

    Published: 8 Nov 2023
    8.8
    High

    CVE-2023-39913

    Last Modified: 13 Feb 2025

    Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK, Apache UIMA Java SDK.This issue affects Apache UIMA Java SDK: before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue. There are several locations in the code where serialized Java objects are deserialized without verifying the data. This affects in particular: * the deserialization of a Java-serialized CAS, but also other binary CAS formats that include TSI information using the CasIOUtils class; * the CAS Editor Eclipse plugin which uses the the CasIOUtils class to load data; * the deserialization of a Java-serialized CAS of the Vinci Analysis Engine service which can receive using Java-serialized CAS objects over network connections; * the CasAnnotationViewerApplet and the CasTreeViewerApplet; * the checkpointing feature of the CPE module. Note that the UIMA framework by default does not start any remotely accessible services (i.e. Vinci) that would be vulnerable to this issue. A user or developer would need to make an active choice to start such a service. However, users or developers may use the CasIOUtils in their own applications and services to parse serialized CAS data. They are affected by this issue unless they ensure that the data passed to CasIOUtils is not a serialized Java object. When using Vinci or using CasIOUtils in own services/applications, the unrestricted deserialization of Java-serialized CAS files may allow arbitrary (remote) code execution. As a remedy, it is possible to set up a global or context-specific ObjectInputFilter (cf. https://openjdk.org/jeps/290  and  https://openjdk.org/jeps/415 ) if running UIMA on a Java version that supports it. Note that Java 1.8 does not support the ObjectInputFilter, so there is no remedy when running on this out-of-support platform. An upgrade to a recent Java version is strongly recommended if you need to secure an UIMA version that is affected by this issue. To mitigate the issue on a Java 9+ platform, you can configure a filter pattern through the "jdk.serialFilter" system property using a semicolon as a separator: To allow deserializing Java-serialized binary CASes, add the classes: * org.apache.uima.cas.impl.CASCompleteSerializer * org.apache.uima.cas.impl.CASMgrSerializer * org.apache.uima.cas.impl.CASSerializer * java.lang.String To allow deserializing CPE Checkpoint data, add the following classes (and any custom classes your application uses to store its checkpoints): * org.apache.uima.collection.impl.cpm.CheckpointData * org.apache.uima.util.ProcessTrace * org.apache.uima.util.impl.ProcessTrace_impl * org.apache.uima.collection.base_cpm.SynchPoint Make sure to use "!*" as the final component to the filter pattern to disallow deserialization of any classes not listed in the pattern. Apache UIMA 3.5.0 uses tightly scoped ObjectInputFilters when reading Java-serialized data depending on the type of data being expected. Configuring a global filter is not necessary with this version.

    Published: 8 Nov 2023
    7.1
    High

    CVE-2023-41111

    Last Modified: 21 Nov 2024

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, Automotive Processor, and Modem (Exynos 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, W920, Modem 5123, Modem 5300, and Auto T5123). Improper handling of a length parameter inconsistency can cause abnormal termination of a mobile phone. This occurs in the RLC task and RLC module.

    Published: 8 Nov 2023
    7.5
    High

    CVE-2023-45875

    Last Modified: 21 Nov 2024

    An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster.

    Published: 8 Nov 2023
    5.5
    Medium

    CVE-2023-46362

    Last Modified: 21 Nov 2024

    jbig2enc v0.28 was discovered to contain a heap-use-after-free via jbig2enc_auto_threshold_using_hash in src/jbig2enc.cc.

    Published: 8 Nov 2023
    5.5
    Medium

    CVE-2023-46363

    Last Modified: 21 Nov 2024

    jbig2enc v0.28 was discovered to contain a SEGV via jbig2_add_page in src/jbig2enc.cc:512.

    Published: 8 Nov 2023
    5.4
    Medium

    CVE-2023-47379

    Last Modified: 21 Nov 2024

    Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality.

    Published: 8 Nov 2023
    9.8
    Critical

    CVE-2023-47397

    Last Modified: 21 Nov 2024

    WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.

    Published: 8 Nov 2023
    7.7
    High

    CVE-2023-5720

    Last Modified: 21 Nov 2024

    A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application.

    Published: 8 Nov 2023
    7.1
    High

    CVE-2023-41112

    Last Modified: 21 Nov 2024

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, Automotive Processor, and Modem (Exynos 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, W920, Modem 5123, Modem 5300, and Auto T5123). A buffer copy, without checking the size of the input, can cause abnormal termination of a mobile phone. This occurs in the RLC task and RLC module.

    Published: 8 Nov 2023
    6.5
    Medium

    CVE-2023-45857

    Last Modified: 21 Nov 2024

    An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.

    Published: 8 Nov 2023
    4
    Medium

    CVE-2023-39197

    Last Modified: 20 Nov 2025

    An out-of-bounds read vulnerability was found in Netfilter Connection Tracking (conntrack) in the Linux kernel. This flaw allows a remote user to disclose sensitive information via the DCCP protocol.

    Published: 8 Nov 2023
    6.5
    Medium

    CVE-2023-6002

    Last Modified: 21 Nov 2024

    YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an unprivileged attacker to forge log entries or inject malicious content into the logs.

    Published: 7 Nov 2023
    5.3
    Medium

    CVE-2023-6001

    Last Modified: 21 Nov 2024

    Prometheus metrics are available without authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment.

    Published: 7 Nov 2023
    9.8
    Critical

    CVE-2023-46800

    Last Modified: 21 Nov 2024

    Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the view_profile.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 7 Nov 2023
    —
    Unknown

    CVE-2023-46799

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 7 Nov 2023
    —
    Unknown

    CVE-2023-46798

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 7 Nov 2023
    —
    Unknown

    CVE-2023-46797

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 7 Nov 2023
    —
    Unknown

    CVE-2023-46796

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 7 Nov 2023
    —
    Unknown

    CVE-2023-46795

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 7 Nov 2023
    —
    Unknown

    CVE-2023-46794

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 7 Nov 2023
    9.8
    Critical

    CVE-2023-46793

    Last Modified: 21 Nov 2024

    Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'day' parameter in the 'register()' function of the functions.php resource does not validate the characters received and they are sent unfiltered to the database.

    Published: 7 Nov 2023
    —
    Unknown

    CVE-2023-46792

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 7 Nov 2023
    —
    Unknown

    CVE-2023-46790

    Last Modified: 2 Jan 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 7 Nov 2023