Filtered by CWE-502
Total 1526 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-21762 1 Microsoft 1 Exchange Server 2024-08-02 8 High
Microsoft Exchange Server Spoofing Vulnerability
CVE-2023-21745 1 Microsoft 1 Exchange Server 2024-08-02 8 High
Microsoft Exchange Server Spoofing Vulnerability
CVE-2023-21713 1 Microsoft 1 Sql Server 2024-08-02 8.8 High
Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2023-21706 1 Microsoft 1 Exchange Server 2024-08-02 8.8 High
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-21703 1 Microsoft 3 Azure Data Box, Azure Data Box Gateway, Azure Stack Edge 2024-08-02 6.5 Medium
Azure Data Box Gateway Remote Code Execution Vulnerability
CVE-2023-21707 1 Microsoft 1 Exchange Server 2024-08-02 8.8 High
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-21710 1 Microsoft 1 Exchange Server 2024-08-02 7.2 High
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-21529 1 Microsoft 1 Exchange Server 2024-08-02 8.8 High
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-21568 1 Microsoft 3 Sql Server, Sql Server 2019 Integration Services, Sql Server 2022 Integration Services 2024-08-02 7.3 High
Microsoft SQL Server Integration Service (VS extension) Remote Code Execution Vulnerability
CVE-2023-21538 3 Fedoraproject, Microsoft, Redhat 5 Fedora, .net, Powershell and 2 more 2024-08-02 7.5 High
.NET Denial of Service Vulnerability
CVE-2023-21205 1 Google 1 Android 2024-08-02 5.5 Medium
In startWpsPinDisplayInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262245376
CVE-2023-21206 1 Google 1 Android 2024-08-02 4.4 Medium
In initiateVenueUrlAnqpQueryInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262245630
CVE-2023-21209 1 Google 1 Android 2024-08-02 6.7 Medium
In multiple functions of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262236273
CVE-2023-21124 1 Google 1 Android 2024-08-02 7.8 High
In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-265798353
CVE-2023-20944 1 Google 1 Android 2024-08-02 7.8 High
In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-244154558
CVE-2023-20888 1 Vmware 1 Vrealize Network Insight 2024-08-02 8.8 High
Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in remote code execution.
CVE-2023-20864 1 Vmware 2 Aria Operations For Logs, Cloud Foundation 2024-08-02 9.8 Critical
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
CVE-2023-20878 1 Vmware 2 Cloud Foundation, Vrealize Operations 2024-08-02 7.2 High
VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system.
CVE-2023-20853 1 Aenrich 1 A\+hrd 2024-08-02 9.8 Critical
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.
CVE-2023-20852 1 Aenrich 1 A\+hrd 2024-08-02 9.8 Critical
aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.