Latest CVE Feed
-
5.5
MEDIUMCVE-2018-20587
Bitcoin Core 0.12.0 through 0.17.1 and Bitcoin Knots 0.12.0 through 0.17.x before 0.17.1.knots20181229 have Incorrect Access Control. Local users can exploit this to steal currency by binding the RPC IPv4 localhost port, and forwarding requests to the IPv... Read more
- Published: Feb. 11, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-12011
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Uninitialized data for socket address leads to information exposure.... Read more
Affected Products : android- Published: Feb. 11, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-0256
Under certain conditions SAP Business One Mobile Android App, version 1.2.12, allows an attacker to access information which would otherwise be restricted.... Read more
Affected Products : business_one- Published: Feb. 15, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-0108
Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable disclosure of information via local access.... Read more
Affected Products : data_center_manager- Published: Feb. 18, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-0111
Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable information disclosure via local access.... Read more
Affected Products : data_center_manager- Published: Feb. 18, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11820
Use of non-time constant memcmp function creates side channel that leaks information and leads to cryptographic issues in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, ... Read more
Affected Products : ipq8074_firmware qca8081_firmware sd_8cx_firmware sdm660_firmware msm8996au_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware +82 more products- Published: Feb. 25, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11864
Bytes can be written to fuses from Secure region which can be read later by HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon ... Read more
Affected Products : ipq8074_firmware qca8081_firmware sd_8cx_firmware sdm660_firmware msm8996au_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware +74 more products- Published: Feb. 25, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-6547
Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.84 and prior. An out-of-bounds read vulnerability may cause the software to crash due to lacking user input validation for processing project files.... Read more
Affected Products : screeneditor- Published: Feb. 28, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-17955
In yast2-multipath before version 4.1.1 a static temporary filename allows local attackers to overwrite files on systems without symlink protection... Read more
Affected Products : yast2-multipath- Published: Mar. 15, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-13103
OX App Suite 7.8.4 and earlier allows SSRF.... Read more
Affected Products : open-xchange_appsuite- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-10020
An issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for x Bresenham parameters.... Read more
Affected Products : xpdf- Published: Mar. 25, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-10025
An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits.... Read more
Affected Products : xpdf- Published: Mar. 25, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-10026
An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec in Function.cc for the psOpRoll case.... Read more
Affected Products : xpdf- Published: Mar. 25, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-15817
FastStone Image Viewer 6.5 has a Read Access Violation on Block Data Move starting at image00400000+0x0000000000002d63 via a crafted image file.... Read more
Affected Products : image_viewer- Published: Mar. 26, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11958
Insufficient protection of keys in keypad can lead HLOS to gain access to confidential keypad input data in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Vo... Read more
Affected Products : sdm660_firmware sd_450_firmware sd_625_firmware mdm9650_firmware mdm9206_firmware mdm9607_firmware sda660_firmware sd_636_firmware mdm9655_firmware sdm630_firmware +50 more products- Published: Apr. 04, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-4143
The IBM Cloud Private Key Management Service (IBM Cloud Private 3.1.1 and 3.1.2) could allow a local user to obtain sensitive from the KMS plugin container log. IBM X-Force ID: 158348.... Read more
Affected Products : cloud_private- Published: Apr. 08, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-0876
An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'.... Read more
Affected Products : open_enclave_software_development_kit- Published: Apr. 09, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-6239
NVIDIA Jetson TX2 contains a vulnerability by means of speculative execution where local and unprivileged code may access the contents of cached information in an unauthorized manner, which may lead to information disclosure. The updates apply to all vers... Read more
Affected Products : jetson_tx2- Published: Apr. 12, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-1725
A vulnerability in the local management CLI implementation for specific commands on the Cisco UCS B-Series Blade Servers could allow an authenticated, local attacker to overwrite an arbitrary file on disk. It is also possible the attacker could inject CLI... Read more
Affected Products : unified_computing_system- Published: Apr. 18, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-11419
vcodec2_hls_filter in libvoipCodec_v7a.so in the WeChat application through 7.0.3 for Android allows attackers to cause a denial of service (application crash) by replacing an emoji file (under the /sdcard/tencent/MicroMsg directory) with a crafted .wxgf ... Read more
Affected Products : wechat- Published: May. 14, 2019
- Modified: Nov. 21, 2024