Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2023-06-08 CVE-2023-33847 Unspecified vulnerability in IBM Cics TX and Txseries for Multiplatform
IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 does not set the secure attribute on authorization tokens or session cookies.
network
high complexity
ibm
3.1
2023-06-07 CVE-2023-24476 Unspecified vulnerability in PTC Vuforia Studio
An attacker with local access to the machine could record the traffic, which could allow them to resend requests without the server authenticating that the user or session are valid.
local
low complexity
ptc
3.3
2023-06-07 CVE-2023-33849 Missing Encryption of Sensitive Data vulnerability in IBM Cics TX and Txseries for Multiplatforms
IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could transmit sensitive information in query parameters that could be intercepted using man in the middle techniques.
network
high complexity
ibm CWE-311
3.7
2023-06-06 CVE-2023-2602 Memory Leak vulnerability in multiple products
A vulnerability was found in the pthread_create() function in libcap.
3.3
2023-06-06 CVE-2023-2961 Unspecified vulnerability in Advancemame Advancecomp
A segmentation fault flaw was found in the Advancecomp package.
local
low complexity
advancemame
3.3
2023-06-02 CVE-2023-3044 Divide By Zero vulnerability in Xpdfreader Xpdf
An excessively large PDF page size (found in fuzz testing, unlikely in normal PDF files) can result in a divide-by-zero in Xpdf's text extraction code. This is related to CVE-2022-30524, but the problem here is caused by a very large page size, rather than by a very large character coordinate.
local
low complexity
xpdfreader CWE-369
3.3
2023-06-02 CVE-2023-2687 Incorrect Calculation of Buffer Size vulnerability in Silabs Gecko Software Development KIT
Buffer overflow in Platform CLI component in Silicon Labs Gecko SDK v4.2.1 and earlier allows user to overwrite limited structures on the heap.
local
low complexity
silabs CWE-131
3.3
2023-06-01 CVE-2023-34339 Unspecified vulnerability in Jetbrains Ktor
In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message
local
low complexity
jetbrains
3.3
2023-06-01 CVE-2023-32712 Improper Encoding or Escaping of Output vulnerability in Splunk
In Splunk Enterprise versions below 9.1.0.2, 9.0.5.1, and 8.2.11.2, an attacker can inject American National Standards Institute (ANSI) escape codes into Splunk log files that, when a vulnerable terminal application reads them, can potentially, at worst, result in possible code execution in the vulnerable application.
network
high complexity
splunk CWE-116
3.1
2023-05-31 CVE-2023-2434 Missing Authorization vulnerability in Kylephillips Nested Pages
The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3.
network
low complexity
kylephillips CWE-862
3.8