Latest CVE Feed
-
5.6
MEDIUMCVE-2024-20309
A vulnerability in auxiliary asynchronous port (AUX) functions of Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload or stop responding. This vulnerability is due to the incorrect handling of specif... Read more
Affected Products : ios_xe- Published: Mar. 27, 2024
- Modified: Jul. 30, 2025
-
5.6
MEDIUMCVE-2023-39593
Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.... Read more
Affected Products : mariadb- Published: Oct. 17, 2024
- Modified: Jul. 10, 2025
-
5.6
MEDIUMCVE-2018-3640
Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System ... Read more
Affected Products : core_i3 core_i5 core_i7 xeon_e3 xeon_e3_1220_v5 xeon_e3_1225_v5 xeon_e3_1230_v5 xeon_e3_1235l_v5 xeon_e3_1240_v5 xeon_e3_1240l_v5 +189 more products- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2020-14758
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes... Read more
- Published: Oct. 21, 2020
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2023-26553
mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when copying the trailing number. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.... Read more
Affected Products : ntp- Published: Apr. 11, 2023
- Modified: Feb. 11, 2025
-
5.6
MEDIUMCVE-2017-12552
A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.... Read more
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2017-12551
A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.... Read more
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2017-12546
A local buffer overflow vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.... Read more
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2025-29592
oasys v1.1 is vulnerable to Directory Traversal in ProcedureController.... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Path Traversal
-
5.6
MEDIUMCVE-2016-3176
Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.... Read more
Affected Products : salt- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
5.6
MEDIUMCVE-2015-7020
The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via unspecified vectors, a different ... Read more
- Published: Oct. 23, 2015
- Modified: Apr. 12, 2025
-
5.6
MEDIUMCVE-2018-19965
An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an i... Read more
- Published: Dec. 08, 2018
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2014-4364
The 802.1X subsystem in Apple iOS before 8 and Apple TV before 7 does not require strong authentication methods, which allows remote attackers to calculate credentials by offering LEAP authentication from a crafted Wi-Fi AP and then performing a cryptogra... Read more
- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
5.6
MEDIUMCVE-2018-16868
A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to ex... Read more
Affected Products : gnutls- Published: Dec. 03, 2018
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2010-5332
In the Linux kernel before 2.6.37, an out of bounds array access happened in drivers/net/mlx4/port.c. When searching for a free entry in either mlx4_register_vlan() or mlx4_register_mac(), and there is no free entry, the loop terminates without updating t... Read more
Affected Products : linux_kernel- Published: Jul. 27, 2019
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2018-12126
Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impac... Read more
- Published: May. 30, 2019
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2018-12127
Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted pr... Read more
- Published: May. 30, 2019
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2018-10846
A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Lucky-13 attack to recover plain text ... Read more
- Published: Aug. 22, 2018
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2023-21960
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access... Read more
Affected Products : weblogic_server- Published: Apr. 18, 2023
- Modified: Nov. 21, 2024
-
5.6
MEDIUMCVE-2017-17565
An issue was discovered in Xen through 4.9.x allowing PV guest OS users to cause a denial of service (host OS crash) if shadow mode and log-dirty mode are in place, because of an incorrect assertion related to M2P.... Read more
Affected Products : xen- Published: Dec. 12, 2017
- Modified: Apr. 20, 2025