‼ CVE-2023-0209 ‼
📖 Read
via "National Vulnerability Database".
NVIDIA DGX-1 SBIOS contains a vulnerability in the Uncore PEI module, where authentication of the code executed by SSA is missing, which may lead to arbitrary code execution, denial of service, escalation of privileges assisted by a firmware implant, information disclosure assisted by a firmware implant, data tampering, and SecureBoot bypass.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25509 ‼
📖 Read
via "National Vulnerability Database".
NVIDIA DGX-1 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of service, and escalation of privileges.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2240 ‼
📖 Read
via "National Vulnerability Database".
Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25513 ‼
📖 Read
via "National Vulnerability Database".
NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in cuobjdump, where an attacker may cause an out-of-bounds read by tricking a user into running cuobjdump on a malformed input file. A successful exploit of this vulnerability may lead to limited denial of service, code execution, and limited information disclosure.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-0207 ‼
📖 Read
via "National Vulnerability Database".
NVIDIA DGX-2 SBIOS contains a vulnerability where an attacker may modify the ServerSetup NVRAM variable at runtime by executing privileged code. A successful exploit of this vulnerability may lead to denial of service.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-0204 ‼
📖 Read
via "National Vulnerability Database".
NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can cause improper handling of exceptional conditions, which may lead to denial of service.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-0201 ‼
📖 Read
via "National Vulnerability Database".
NVIDIA DGX-2 SBIOS contains a vulnerability in Bds, where a user with high privileges can cause a write beyond the bounds of an indexable resource, which may lead to code execution, denial of service, compromised integrity, and information disclosure.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25505 ‼
📖 Read
via "National Vulnerability Database".
NVIDIA DGX-1 BMC contains a vulnerability in the IPMI handler of the AMI MegaRAC BMC , where an attacker with the appropriate level of authorization can cause a buffer overflow, which may lead to denial of service, information disclosure, or arbitrary code execution.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25512 ‼
📖 Read
via "National Vulnerability Database".
NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in cuobjdump, where an attacker may cause an out-of-bounds memory read by running cuobjdump on a malformed input file. A successful exploit of this vulnerability may lead to limited denial of service, code execution, and limited information disclosure.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-0190 ‼
📖 Read
via "National Vulnerability Database".
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a NULL pointer dereference may lead to denial of service.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-0200 ‼
📖 Read
via "National Vulnerability Database".
NVIDIA DGX-2 contains a vulnerability in OFBD where a user with high privileges and a pre-conditioned heap can cause an access beyond a buffers end, which may lead to code execution, escalation of privileges, denial of service, and information disclosure.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-0199 ‼
📖 Read
via "National Vulnerability Database".
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds write can lead to denial of service and data tampering.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-0203 ‼
📖 Read
via "National Vulnerability Database".
NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can exploit insufficient granularity of access control, which may lead to denial of service.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2243 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file users/registration.php of the component POST Parameter Handler. The manipulation of the argument fullname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-227228.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2241 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the function readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The name of the patch is 535a786f124b739e3c857529cecc29e4eeb79778. It is recommended to apply a patch to fix this issue. VDB-227226 is the identifier assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2242 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component GET Parameter Handler. The manipulation of the argument c/s leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227227.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2239 ‼
📖 Read
via "National Vulnerability Database".
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository microweber/microweber prior to 1.3.4.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2245 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in hansunCMS 1.4.3. It has been declared as critical. This vulnerability affects unknown code of the file /ueditor/net/controller.ashx?action=catchimage. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-227230 is the identifier assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2244 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. This affects an unknown part of the file /admin/orders/update_status.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227229 was assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-44582 ‼
📖 Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Apptivo Apptivo Business Site CRM plugin <=Â 3.0.12 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-44631 ‼
📖 Read
via "National Vulnerability Database".
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in 1app Technologies, Inc 1app Business Forms plugin <=Â 1.0.0 versions.📖 Read
via "National Vulnerability Database".
👍1