CVE Notify
19.6K subscribers
4 photos
238K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2023-37711
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the deviceId parameter in the saveParentControlInfo function.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-37710
Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the wpapsk_crypto parameter in the fromSetWirelessRepeat function.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-37706
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the entrys parameter in the fromAddressNat function.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-32046
Windows MSHTML Platform Elevation of Privilege Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-32040
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-32039
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-32049
Windows SmartScreen Security Feature Bypass Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-32047
Paint 3D Remote Code Execution Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-32050
Windows Installer Elevation of Privilege Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-32042
OLE Automation Information Disclosure Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-37463
cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syntax with a spec. Three polynomial time complexity issues in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. These vulnerabilities have been patched in 0.29.0.gfm.12.


๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-30565
An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-30564
Alaris Systems Manager does not perform input validation during the Device Import Function.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-30563
A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-30562
A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs.





๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-30561
The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read or modify data by attaching a specially crafted device while an infusion is running.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-32041
Windows Update Orchestrator Service Information Disclosure Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-33148
Microsoft Office Elevation of Privilege Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-33134
Microsoft SharePoint Server Remote Code Execution Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-33149
Microsoft Office Graphics Remote Code Execution Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-33159
Microsoft SharePoint Server Spoofing Vulnerability

๐ŸŽ–@cveNotify