CVE List - 2023 / December

Showing 301 - 400 of 2673 CVEs for December 2023 (Page 4 of 27)

CVE ID Date Title
CVE-2023-40461 2023-12-04 Cross-site scripting vulnerability in ACEManager
CVE-2023-49286 2023-12-04 Denial of Service in Helper Process management
CVE-2023-40462 2023-12-04 Improper input leads to DoS
CVE-2023-49285 2023-12-04 Denial of Service in HTTP Message Processing in Squid
CVE-2023-40463 2023-12-04 Use of Hard-Coded Credentials
CVE-2023-40464 2023-12-04 Use of hardcoded certificate and private key
CVE-2023-40465 2023-12-04 Improper input leads to DoS
CVE-2023-49293 2023-12-04 Cross-site Scripting in `server.transformIndexHtml` via URL payload in vite
CVE-2023-5944 2023-12-04 Delta Electronics DOPSoft Stack-based Buffer Overflow
CVE-2023-49292 2023-12-04 Possible private key restoration in go package github.com/ecies/go
CVE-2023-49291 2023-12-04 Improper Sanitization of Branch Name Leads to Arbitrary Code Injection
CVE-2023-49290 2023-12-04 Malicious parameters can cause a denial of service in lestrrat-go/jwx
CVE-2023-49284 2023-12-04 Command substitution output can trigger shell expansion in fish shell
CVE-2023-49289 2023-12-04 Cross-site Scripting in Ajax.NET Professional
CVE-2023-5808 2023-12-04 System Management Unit (SMU) versions prior to 14.8.7825.01, used to manage Hitachi Vantara NAS products are susceptible to unintended information disclosure via unprivileged access to HNAS configuration backup and diagnostic data.
CVE-2022-47531 2023-12-05 An issue was discovered in Ericsson Evolved Packet Gateway (EPG) versions 3.x before 3.25 and 2.x before 2.16, allows authenticated users to bypass system CLI and execute commands they are...
CVE-2023-37572 2023-12-05 Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive information via weak permissions in OSF_discovery service. The service executable could be changed or...
CVE-2023-43472 2023-12-05 An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API.
CVE-2023-47304 2023-12-05 An issue was discovered in Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1, allows local attackers to bypass UART authentication controls and read/write arbitrary values to the memory of the device.
CVE-2023-49372 2023-12-05 JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/save.
CVE-2023-49373 2023-12-05 JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/slide/delete.
CVE-2023-49374 2023-12-05 JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/update.
CVE-2023-49375 2023-12-05 JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/update.
CVE-2023-49376 2023-12-05 JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/delete.
CVE-2023-49377 2023-12-05 JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/update.
CVE-2023-49378 2023-12-05 JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/form/save.
CVE-2023-49379 2023-12-05 JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /admin/friend_link/save.
CVE-2023-49380 2023-12-05 JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/delete.
CVE-2023-49381 2023-12-05 JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/update.
CVE-2023-49382 2023-12-05 JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/delete.
CVE-2023-49383 2023-12-05 JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/save.
CVE-2023-49395 2023-12-05 JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/update.
CVE-2023-49396 2023-12-05 JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/save.
CVE-2023-49397 2023-12-05 JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/updateStatus.
CVE-2023-49398 2023-12-05 JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/delete.
CVE-2023-49446 2023-12-05 JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/save.
CVE-2023-49447 2023-12-05 JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/update.
CVE-2023-49448 2023-12-05 JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete.
CVE-2023-48315 2023-12-05 Azure RTOS NetX Duo Remote Code Execution Vulnerability
CVE-2023-48316 2023-12-05 Azure RTOS NetX Duo Remote Code Execution Vulnerability
CVE-2023-48691 2023-12-05 Azure RTOS NetX Duo Remote Code Execution Vulnerability
CVE-2023-48692 2023-12-05 Azure RTOS NetX Duo Remote Code Execution Vulnerability
CVE-2023-48693 2023-12-05 Azure RTOS ThreadX Remote Code Execution Vulnerability
CVE-2023-48694 2023-12-05 Azure RTOS USBX Remote Code Execution Vulnerability
CVE-2023-48695 2023-12-05 Azure RTOS USBX Remote Code Execution Vulnerability
CVE-2023-48696 2023-12-05 Azure RTOS USBX Remote Code Execution Vulnerability
CVE-2023-48697 2023-12-05 Azure RTOS USBX Remote Code Execution Vulnerability
CVE-2023-48698 2023-12-05 Azure RTOS USBX Remote Code Execution Vulnerability
CVE-2023-42556 2023-12-05 Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get sensitive information.
CVE-2023-42557 2023-12-05 Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute arbitrary code.
CVE-2023-42558 2023-12-05 Out of bounds write vulnerability in HDCP in HAL prior to SMR Dec-2023 Release 1 allows attacker to perform code execution.
CVE-2023-42559 2023-12-05 Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system time.
CVE-2023-42560 2023-12-05 Heap out-of-bounds write vulnerability in dec_mono_audb of libsavsac.so prior to SMR Dec-2023 Release 1 allows an attacker to execute arbitrary code.
CVE-2023-42561 2023-12-05 Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.
CVE-2023-42562 2023-12-05 Integer overflow vulnerability in detectionFindFaceSupportMultiInstance of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.
CVE-2023-42564 2023-12-05 Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with system privilege.
CVE-2023-42565 2023-12-05 Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrary code.
CVE-2023-42566 2023-12-05 Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers to execute arbitrary code.
CVE-2023-42567 2023-12-05 Improper size check vulnerability in softsimd prior to SMR Dec-2023 Release 1 allows stack-based buffer overflow.
CVE-2023-42568 2023-12-05 Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.
CVE-2023-42569 2023-12-05 Improper authorization verification vulnerability in AR Emoji prior to SMR Dec-2023 Release 1 allows attackers to read sandbox data of AR Emoji.
CVE-2023-42570 2023-12-05 Improper access control vulnerability in KnoxCustomManagerService prior to SMR Dec-2023 Release 1 allows attacker to access device SIM PIN.
CVE-2023-42571 2023-12-05 Abuse of remote unlock in Find My Mobile prior to version 7.3.13.4 allows physical attacker to unlock the device remotely by resetting the Samsung Account password with SMS verification when...
CVE-2023-42572 2023-12-05 Implicit intent hijacking vulnerability in Samsung Account Web SDK prior to version 1.5.24 allows attacker to get sensitive information.
CVE-2023-42573 2023-12-05 PendingIntent hijacking vulnerability in Search Widget prior to version 3.4 in China models allows local attackers to access data.
CVE-2023-42574 2023-12-05 Improper access control vulnerablility in GameHomeCN prior to version 4.2.60.2 allows local attackers to launch arbitrary activity in GameHomeCN.
CVE-2023-42575 2023-12-05 Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid flag setting.
CVE-2023-42576 2023-12-05 Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid exception handler.
CVE-2023-42577 2023-12-05 Improper Access Control in Samsung Voice Recorder prior to versions 21.4.15.01 in Android 12 and Android 13, 21.4.50.17 in Android 14 allows physical attackers to access Voice Recorder information on...
CVE-2023-42578 2023-12-05 Improper handling of insufficient permissions or privileges vulnerability in Samsung Data Store prior to version 5.2.00.7 allows remote attackers to access location information without permission.
CVE-2023-42579 2023-12-05 Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45...
CVE-2023-42580 2023-12-05 Improper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to install APK from Galaxy Store.
CVE-2023-42581 2023-12-05 Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data.
CVE-2023-42563 2023-12-05 Integer overflow vulnerability in landmarkCopyImageToNative of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.
CVE-2023-21634 2023-12-05 Improper Restriction of Operations within the Bounds of a Memory Buffer in Radio Interface Layer
CVE-2023-22383 2023-12-05 Use After Free in Camera
CVE-2023-22668 2023-12-05 Use After Free in Audio
CVE-2023-28546 2023-12-05 Buffer Copy Without Checking Size of Input in SPS Applications
CVE-2023-28550 2023-12-05 Improper Restriction of Operations within the Bounds of a Memory Buffer in MPP Performance
CVE-2023-28551 2023-12-05 Improper Restriction of Operations within the Bounds of a Memory Buffer in UTILS
CVE-2023-28579 2023-12-05 Buffer Copy Without Checking Size of Input in WLAN Host
CVE-2023-28580 2023-12-05 Buffer Copy Without Checking Size of Input in WLAN Host
CVE-2023-28585 2023-12-05 Integer Overflow to Buffer Overflow in TZ Secure OS
CVE-2023-28586 2023-12-05 Improper Restriction of Operation within the Bounds of a Memory Buffer in TZ Secure OS
CVE-2023-28587 2023-12-05 Improper Restriction of Operations within the Bounds of a Memory Buffer in BT Controller
CVE-2023-28588 2023-12-05 Integer Overflow or Wraparound in Bluetooth Host
CVE-2023-33017 2023-12-05 Buffer Copy Without Checking Size of Input in Boot
CVE-2023-33018 2023-12-05 Integer Overflow to Buffer Overflow in User Identity Module
CVE-2023-33022 2023-12-05 Integer Overflow to Buffer Overflow in HLOS
CVE-2023-33024 2023-12-05 Buffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in Radio Interface Layer
CVE-2023-33041 2023-12-05 Reachable assertion in WLAN Firmware
CVE-2023-33042 2023-12-05 Improper Input Validation in Modem
CVE-2023-33043 2023-12-05 Reachable Assertion in Modem
CVE-2023-33044 2023-12-05 Reachable Assertion in Data Modem
CVE-2023-33053 2023-12-05 Improper Validation of Array Index in Kernel
CVE-2023-33054 2023-12-05 Improper Authentication in GPS HLOS Driver
CVE-2023-33063 2023-12-05 Use After Free in DSP Services
CVE-2023-33070 2023-12-05 Improper Authentication in Automotive OS
CVE-2023-33071 2023-12-05 Improper Access Control in Automotive OS Platform Android
CVE-2023-33079 2023-12-05 Use of Out-of-range Pointer Offset in Audio