CVE-2023-42908
https://notcve.org/view.php?id=CVE-2023-42908
Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution. • http://seclists.org/fulldisclosure/2023/Dec/9 https://support.apple.com/en-us/HT214036 • CWE-787: Out-of-bounds Write •
CVE-2023-42903
https://notcve.org/view.php?id=CVE-2023-42903
Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution. • http://seclists.org/fulldisclosure/2023/Dec/9 https://support.apple.com/en-us/HT214036 • CWE-787: Out-of-bounds Write •
CVE-2023-42902 – Apple macOS VideoToolbox Out-Of-Bounds Write Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2023-42902
Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution. • http://seclists.org/fulldisclosure/2023/Dec/9 https://support.apple.com/en-us/HT214036 • CWE-787: Out-of-bounds Write •
CVE-2023-43364
https://notcve.org/view.php?id=CVE-2023-43364
main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution. main.py en Searchor anterior a 2.4.2 usa eval en la entrada CLI, lo que puede provocar la ejecución inesperada de código. • https://github.com/libertycityhacker/CVE-2023-43364-Exploit-CVE https://github.com/ArjunSharda/Searchor/commit/16016506f7bf92b0f21f51841d599126d6fcd15b https://github.com/ArjunSharda/Searchor/pull/130 https://github.com/advisories/GHSA-66m2-493m-crh2 https://github.com/nexis-nexis/Searchor-2.4.0-POC-Exploit- https://github.com/nikn0laty/Exploit-for-Searchor-2.4.0-Arbitrary-CMD-Injection • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2023-5500 – Frauscher: FDS102 for FAdC/FAdCi remote code execution vulnerability
https://notcve.org/view.php?id=CVE-2023-5500
This vulnerability allows an remote attacker with low privileges to misuse Improper Control of Generation of Code ('Code Injection') to gain full control of the affected device. • https://cert.vde.com/en/advisories/VDE-2023-049 • CWE-94: Improper Control of Generation of Code ('Code Injection') •