Show filters
1,622 Total Results
Displaying 281-290 of 1,622
Sort by:
Attacker Value
Unknown
CVE-2023-27198
Disclosure Date: July 05, 2023 (last updated October 08, 2023)
PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow the execution of arbitrary commands by using the exec service and including a specific word in the command to be executed. The attacker must have physical USB access to the device in order to exploit this vulnerability.
0
Attacker Value
Unknown
CVE-2023-21629
Disclosure Date: July 04, 2023 (last updated October 08, 2023)
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
0
Attacker Value
Unknown
CVE-2023-3497
Disclosure Date: July 03, 2023 (last updated October 08, 2023)
Out of bounds read in Google Security Processor firmware in Google Chrome on Chrome OS prior to 114.0.5735.90 allowed a local attacker to perform denial of service via physical access to the device. (Chromium security severity: Medium)
0
Attacker Value
Unknown
CVE-2023-21513
Disclosure Date: June 28, 2023 (last updated October 08, 2023)
Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition.
0
Attacker Value
Unknown
CVE-2023-35163
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
Vega is a decentralized trading platform that allows pseudo-anonymous trading of derivatives on a blockchain. Prior to version 0.71.6, a vulnerability exists that allows a malicious validator to trick the Vega network into re-processing past Ethereum events from Vega’s Ethereum bridge. For example, a deposit to the collateral bridge for 100USDT that credits a party’s general account on Vega, can be re-processed 50 times resulting in 5000USDT in that party’s general account. This is without depositing any more than the original 100USDT on the bridge. Despite this exploit requiring access to a validator's Vega key, a validator key can be obtained at the small cost of 3000VEGA, the amount needed to announce a new node onto the network.
A patch is available in version 0.71.6. No known workarounds are available, however there are mitigations in place should this vulnerability be exploited. There are monitoring alerts for `mainnet1` in place to identify any issues of this nature including …
0
Attacker Value
Unknown
CVE-2023-32417
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
This issue was addressed by restricting options offered on a locked device. This issue is fixed in watchOS 9.5. An attacker with physical access to a locked Apple Watch may be able to view user photos or contacts via accessibility features.
0
Attacker Value
Unknown
CVE-2023-32394
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. A person with physical access to a device may be able to view contact information from the lock screen.
0
Attacker Value
Unknown
CVE-2023-32391
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, watchOS 9.5, iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4. A shortcut may be able to use sensitive data with certain actions without prompting the user.
0
Attacker Value
Unknown
CVE-2023-32390
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, macOS Ventura 13.4. Photos belonging to the Hidden Photos Album could be viewed without authentication through Visual Lookup.
0
Attacker Value
Unknown
CVE-2023-32365
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, iOS 16.5 and iPadOS 16.5. Shake-to-undo may allow a deleted photo to be re-surfaced without authentication.
0