Show filters
603 Total Results
Displaying 91-100 of 603
Sort by:
Attacker Value
Unknown

CVE-2023-38428

Disclosure Date: July 18, 2023 (last updated December 16, 2023)
An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not consider the address of security buffer, leading to an out-of-bounds read.
Attacker Value
Unknown

CVE-2023-38426

Disclosure Date: July 18, 2023 (last updated December 23, 2023)
An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when create_context's name_len is larger than the tag length.
Attacker Value
Unknown

CVE-2023-2763

Disclosure Date: July 12, 2023 (last updated October 08, 2023)
Use-After-Free, Out-of-bounds Write and Heap-based Buffer Overflow vulnerabilities exist in the DWG and DXF file reading procedure in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted DWG or DXF file.
Attacker Value
Unknown

CVE-2023-2762

Disclosure Date: July 12, 2023 (last updated October 08, 2023)
A Use-After-Free vulnerability in SLDPRT file reading procedure exists in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted SLDPRT file.
Attacker Value
Unknown

CVE-2023-31199

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
Improper access control in the Intel(R) Solid State Drive Toolbox(TM) before version 3.4.5 may allow a privileged user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2023-30986

Disclosure Date: May 09, 2023 (last updated February 24, 2025)
A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 3), Solid Edge SE2023 (All versions < V223.0 Update 2). Affected applications contain a memory corruption vulnerability while parsing specially crafted STP files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19561)
Attacker Value
Unknown

CVE-2023-30985

Disclosure Date: May 09, 2023 (last updated February 24, 2025)
A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 3), Solid Edge SE2023 (All versions < V223.0 Update 2). Affected applications contain an out of bounds read past the end of an allocated buffer while parsing a specially crafted OBJ file. This vulnerability could allow an attacker to disclose sensitive information. (ZDI-CAN-19426)
Attacker Value
Unknown

CVE-2023-31407

Disclosure Date: May 09, 2023 (last updated February 24, 2025)
SAP Business Planning and Consolidation - versions 740, 750, allows an authorized attacker to upload a malicious file, resulting in Cross-Site Scripting vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application.
Attacker Value
Unknown

CVE-2023-2007

Disclosure Date: April 24, 2023 (last updated February 24, 2025)
The specific flaw exists within the DPT I2O Controller driver. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel.
Attacker Value
Unknown

CVE-2023-1377

Disclosure Date: April 03, 2023 (last updated October 08, 2023)
The Solidres WordPress plugin through 0.9.4 does not sanitise and escape numerous parameter before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin