
CVE-2023-0664
https://notcve.org/view.php?id=CVE-2023-0664
29 Mar 2023 — A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's Windows installer via repair custom actions to elevate their privileges on the system. • https://bugzilla.redhat.com/show_bug.cgi?id=2167423 • CWE-250: Execution with Unnecessary Privileges CWE-269: Improper Privilege Management •

CVE-2023-25903 – Adobe Dimension USDZ files Integer Overflow or Wraparound Arbitrary code execution
https://notcve.org/view.php?id=CVE-2023-25903
28 Mar 2023 — Adobe Dimension versions 3.4.7 (and earlier) is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. • https://helpx.adobe.com/security/products/dimension/apsb23-20.html • CWE-190: Integer Overflow or Wraparound •

CVE-2023-25904 – Adobe Dimension Out-of-bounds Read USDZ file Arbitrary code execution
https://notcve.org/view.php?id=CVE-2023-25904
28 Mar 2023 — Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. • https://helpx.adobe.com/security/products/dimension/apsb23-20.html • CWE-125: Out-of-bounds Read •

CVE-2022-4126 – Use of Default Password
https://notcve.org/view.php?id=CVE-2022-4126
27 Mar 2023 — Use of Default Password vulnerability in ABB RCCMD on Windows, Linux, MacOS allows Try Common or Default Usernames and Passwords.This issue affects RCCMD: before 4.40 230207. • https://search.abb.com/library/Download.aspx?DocumentID=2CMT006099_EN&LanguageCode=en&DocumentPartId=&Action=Launch • CWE-287: Improper Authentication CWE-1393: Use of Default Password •

CVE-2023-25908 – Adobe Photoshop SVG file Use After Free Arbitrary code execution
https://notcve.org/view.php?id=CVE-2023-25908
27 Mar 2023 — Adobe Photoshop versions 23.5.3 (and earlier) and 24.1.1 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. • https://helpx.adobe.com/security/products/photoshop/apsb23-23.html • CWE-416: Use After Free •

CVE-2023-28597 – Improper trust boundary implementation for SMB in Zoom Clients
https://notcve.org/view.php?id=CVE-2023-28597
27 Mar 2023 — Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a user's device and data, and remote code execution. • https://explore.zoom.us/en/trust/security/security-bulletin • CWE-501: Trust Boundary Violation •

CVE-2023-26283 – IBM WebSphere Application Server cross-site scripting
https://notcve.org/view.php?id=CVE-2023-26283
22 Mar 2023 — IBM WebSphere Application Server 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 248416. • https://exchange.xforce.ibmcloud.com/vulnerabilities/248416 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-27875 – IBM Aspera Faspex improper access controls
https://notcve.org/view.php?id=CVE-2023-27875
16 Mar 2023 — IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Force ID: 249847. • https://exchange.xforce.ibmcloud.com/vulnerabilities/249847 • CWE-284: Improper Access Control •

CVE-2023-25859 – Adobe Illustrator Improper Input Validation Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2023-25859
16 Mar 2023 — Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Illustrator. User interaction is required to exploit this vulnerability in that the target must visit a... • https://helpx.adobe.com/security/products/illustrator/apsb23-19.html • CWE-20: Improper Input Validation •

CVE-2023-25863 – Adobe Substance 3D Stager USDC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2023-25863
16 Mar 2023 — Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Adobe Substance 3D Stager versions 2.0.0 (y anteriores) se ven afectados por una vulnerabilidad de lectu... • https://helpx.adobe.com/security/products/substance3d_stager/apsb23-22.html • CWE-125: Out-of-bounds Read •