Latest CVE Feed
-
5.6
MEDIUMCVE-2017-12548
A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.... Read more
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2017-12550
A local security misconfiguration vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.... Read more
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2022-33748
lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanup call was inserted on an error handling path. While doing so, locking requirements were not paid attention to. As a result two cooperating guests granting each othe... Read more
- Published: Oct. 11, 2022
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2022-22712
Windows Hyper-V Denial of Service Vulnerability... Read more
Affected Products : windows_10 windows_server_2019 windows_server windows_10_1809 windows_10_21h2 windows_server_2022 windows_11_21h2 windows_11 windows windows_10_21h1 +2 more products- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2017-14317
A domain cleanup issue was discovered in the C xenstore daemon (aka cxenstored) in Xen through 4.9.x. When shutting down a VM with a stubdomain, a race in cxenstored may cause a double-free. The xenstored daemon may crash, resulting in a DoS of any parts ... Read more
Affected Products : xen- Published: Sep. 12, 2017
- Modified: Apr. 20, 2025
-
5.6
MEDIUMCVE-2020-0551
Load value injection in some Intel(R) Processors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. The list of affected products is provided in intel-sa-00334... Read more
Affected Products : xeon_e-2124 xeon_e-2124g xeon_e-2126g xeon_e-2134 xeon_e-2136 xeon_e-2144g xeon_e-2146g xeon_e-2174g xeon_e-2176g xeon_e-2176m +1311 more products- Published: Mar. 12, 2020
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2019-14826
A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.... Read more
- Published: Sep. 17, 2019
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2018-3646
Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault an... Read more
- Published: Aug. 14, 2018
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2016-8924
IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's sessio... Read more
Affected Products : maximo_asset_management- Published: Apr. 26, 2017
- Modified: Apr. 20, 2025
-
5.6
MEDIUMCVE-2005-0109
Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensi... Read more
Affected Products : enterprise_linux enterprise_linux_desktop solaris freebsd unixware ubuntu_linux fedora_core openserver- Published: Mar. 05, 2005
- Modified: Apr. 03, 2025
-
5.6
MEDIUMCVE-2016-5242
The p2m_teardown function in arch/arm/p2m.c in Xen 4.4.x through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (NULL pointer dereference and host OS crash) by creating concurrent domains and holding refere... Read more
Affected Products : xen- Published: Jun. 07, 2016
- Modified: Apr. 12, 2025
-
5.6
MEDIUMCVE-2016-4811
The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.15.1 and earlier for Android and 1.13.0 and earlier for iOS allows man-in-the-middle attackers to obtain API access via unspecified vectors.... Read more
Affected Products : japan_connected-free_wi-fi- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
5.6
MEDIUMCVE-2022-32482
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable. ... Read more
Affected Products : cpg_bios alienware_m15_r6_firmware alienware_m15_r7_firmware chengming_3900_firmware g15_5510_firmware g15_5511_firmware g15_5520_firmware g16_7620_firmware g3_3500_firmware g5_15_5500_firmware +369 more products- Published: Feb. 01, 2023
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2019-3901
A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid programs. As no relevant locks (in particular the cred_guard_mutex) are held during the ptrace_may_access() call, it is possible for the specified target task ... Read more
Affected Products : linux_kernel debian_linux hci_management_node solidfire cn1610_firmware vasa_provider_for_clustered_data_ontap snapprotect active_iq_unified_manager_for_vmware_vsphere virtual_storage_console_for_vmware_vsphere storage_replication_adapter_for_clustered_data_ontap_for_vmware_vsphere +1 more products- Published: Apr. 22, 2019
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2019-2525
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Difficult to exploit vulnerability allows low privileged attacker with logon to... Read more
Affected Products : vm_virtualbox- Published: Jan. 16, 2019
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2024-36894
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix race between aio_cancel() and AIO request complete FFS based applications can utilize the aio_cancel() callback to dequeue pending USB requests submitted to the U... Read more
Affected Products : linux_kernel- Published: May. 30, 2024
- Modified: Apr. 01, 2025
-
5.6
MEDIUMCVE-2017-9310
QEMU (aka Quick Emulator), when built with the e1000e NIC emulation support, allows local guest OS privileged users to cause a denial of service (infinite loop) via vectors related to setting the initial receive / transmit descriptor head (TDH/RDH) outsid... Read more
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
5.6
MEDIUMCVE-2015-7019
The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via unspecified vectors, a different ... Read more
- Published: Oct. 23, 2015
- Modified: Apr. 12, 2025
-
5.6
MEDIUMCVE-2020-8911
A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to encrypt files with AES-CBC without computing a Message Authentication Code (MAC), which then allows an attacker who has write access to... Read more
Affected Products : aws_s3_crypto_sdk- Published: Aug. 11, 2020
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2020-7765
This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the DeepCopy.ts file. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.... Read more
Affected Products : firebase\/util- Published: Nov. 16, 2020
- Modified: Nov. 21, 2024