NVD disclosure day

Published threat advisories for August 14, 2023

CVE advisoryKnown Exploit

CVE-2022-48503

Apple Software Vulnerability Allows Code Execution via Web Content

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Apple software and Safari allows arbitrary code execution when processing web content. This impacts affected organizations by posing a risk to data and systems. Attackers could exploit this flaw to gain unauthorized access.

• CISA KEV

CVE advisoryCRITICAL

CVE-2023-30187

ONLYOFFICE DocumentServer Out-of-Bounds Memory Access Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An out-of-bounds memory access vulnerability in ONLYOFFICE DocumentServer could allow remote attackers to execute arbitrary code by uploading a crafted JavaScript file. This could affect the confidentiality, integrity, and availability of systems processing documents.

CVE advisoryCRITICAL

CVE-2023-30186

ONLYOFFICE DocumentServer Use-After-Free Vulnerability Allows Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A use-after-free vulnerability in ONLYOFFICE DocumentServer can allow remote attackers to run arbitrary code by tricking users into opening a specially crafted JavaScript file. This could lead to system compromise if the affected technology is reachable.

CVE advisoryCRITICAL

CVE-2023-37847

Novel-Plus SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability in novel-plus, a web-based application for online reading and content management, allows unauthenticated attackers to execute arbitrary SQL commands. This could impact data integrity and confidentiality by enabling unauthorized access or manipulation of sensitive information when the appli