Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In March 2023
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due to enabling XML entity substitution that may result in XML external entity injection. An attacker could exploit this vulnerability by submitting a crafted DMG file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to leak bytes from any file that may be read by the ClamAV scanning process.
CVSS Score
5.3
EPSS Score
0.07
Published
2023-03-01
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Liman Central Management System Liman MYS (HTTP/Controllers, CronMail, Jobs modules) allows Command Injection. This issue affects Liman Central Management System: from 1.7.0 before 1.8.3-462.
CVSS Score
8.8
EPSS Score
0.018
Published
2023-03-01
A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed environment variables. Impacts Zowe CLI.
CVSS Score
3.3
EPSS Score
0.003
Published
2023-03-01
A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a configured rule, thereby allowing traffic onto a network that should have been blocked. This vulnerability exists because malformed, encoded traffic is not properly detected. An attacker could exploit this vulnerability by connecting through an affected device to a malicious server and receiving malformed HTTP responses. A successful exploit could allow the attacker to bypass an explicit block rule and receive traffic that should have been rejected by the device.
CVSS Score
5.3
EPSS Score
0.007
Published
2023-03-01
When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an SMT mode switch potentially resulting in information disclosure.
CVSS Score
4.7
EPSS Score
0.003
Published
2023-03-01
Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to modify files potentially leading to privilege escalation and code execution by the lower privileged user.
CVSS Score
7.8
EPSS Score
0.002
Published
2023-03-01
HPE OneView for VMware vCenter, in certain circumstances, may disclose the “HPE OneView” Username and Password.
CVSS Score
5.5
EPSS Score
0.002
Published
2023-03-01
Unauthenticated Java deserialization vulnerability in Serviceguard Manager
CVSS Score
9.8
EPSS Score
0.008
Published
2023-03-01
Pre-auth memory corruption in HPE Serviceguard
CVSS Score
9.8
EPSS Score
0.007
Published
2023-03-01
Unauthenticated server side request forgery in HPE Serviceguard Manager
CVSS Score
9.8
EPSS Score
0.006
Published
2023-03-01


Contact Us

Shodan ® - All rights reserved