
CVE-2023-27908 – Autodesk On-Demand Install Services Link Following Local Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2023-27908
24 May 2023 — A maliciously crafted DLL file can be forced to write beyond allocated boundaries in the Autodesk installer when parsing the DLL files and could lead to a Privilege Escalation vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Autodesk On-Demand Install Services. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the AdskAccessServiceHos... • https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0010 • CWE-427: Uncontrolled Search Path Element •

CVE-2023-0860 – Improper Restriction of Excessive Authentication Attempts in modoboa/modoboa-installer
https://notcve.org/view.php?id=CVE-2023-0860
16 Feb 2023 — Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4. • https://github.com/0xsu3ks/CVE-2023-0860 • CWE-307: Improper Restriction of Excessive Authentication Attempts •