Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2023-40596

Description: In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk Enterprise references an insecure path for the OPENSSLDIR build definition. An attacker can abuse this reference and subsequently install malicious code to achieve privilege escalation on the Windows machine.

CVSS: HIGH (7.0)

EPSS Score: 0.04%

Source: CVE
December 11th, 2024 (4 months ago)

CVE-2023-40595

Description: In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they can then use to serialize untrusted data. The attacker can use the query to execute arbitrary code.

CVSS: HIGH (8.8)

EPSS Score: 0.1%

Source: CVE
December 11th, 2024 (4 months ago)

CVE-2023-3997

Description: Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can send Splunk SOAR a maliciously crafted web request containing special ANSI characters to cause log file poisoning. When a terminal user attempts to view the poisoned logs, this can tamper with the terminal and cause possible malicious code execution from the terminal user’s action.

CVSS: HIGH (8.6)

EPSS Score: 0.06%

Source: CVE
December 11th, 2024 (4 months ago)

CVE-2023-38171

Description: Microsoft QUIC Denial of Service Vulnerability

CVSS: HIGH (7.5)

EPSS Score: 0.19%

Source: CVE
December 11th, 2024 (4 months ago)

CVE-2023-38166

Description: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVSS: HIGH (8.1)

EPSS Score: 0.23%

Source: CVE
December 11th, 2024 (4 months ago)

CVE-2023-38159

Description: Windows Graphics Component Elevation of Privilege Vulnerability

CVSS: HIGH (7.0)

EPSS Score: 0.04%

Source: CVE
December 11th, 2024 (4 months ago)

CVE-2023-36902

Description: Windows Runtime Remote Code Execution Vulnerability

CVSS: HIGH (7.0)

EPSS Score: 0.23%

Source: CVE
December 11th, 2024 (4 months ago)

CVE-2023-36790

Description: Windows RDP Encoder Mirror Driver Elevation of Privilege Vulnerability

CVSS: HIGH (7.8)

EPSS Score: 0.05%

Source: CVE
December 11th, 2024 (4 months ago)

CVE-2023-36789

Description: Skype for Business Remote Code Execution Vulnerability

CVSS: HIGH (7.2)

EPSS Score: 0.2%

Source: CVE
December 11th, 2024 (4 months ago)

CVE-2023-36786

Description: Skype for Business Remote Code Execution Vulnerability

CVSS: HIGH (7.2)

EPSS Score: 0.22%

Source: CVE
December 11th, 2024 (4 months ago)