Latest CVE Feed
-
5.5
MEDIUMCVE-2021-39548
An issue was discovered in sela through 20200412. A NULL pointer dereference exists in the function frame::FrameDecoder::process() located in frame_decoder.c. It allows an attacker to cause Denial of Service.... Read more
Affected Products : sela- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39555
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function InfoOutputDev::type3D0() located in InfoOutputDev.cc. It allows an attacker to cause Denial of Service.... Read more
Affected Products : swftools- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-0371
The Tivoli Storage Manager (TSM) password may be displayed in plain text via application trace output while application tracing is enabled.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-8929
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-8963
IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-6237
The build_huffcodes function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds write) via a crafted jpeg file.... Read more
Affected Products : lepton- Published: Feb. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2021-33923
Insecure permissions in Confluent Ansible (cp-ansible) 5.5.0, 5.5.1, 5.5.2 and 6.0.0 allows local attackers to access some sensitive information (private keys, state database).... Read more
Affected Products : cp-ansible- Published: Sep. 29, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-8981
IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2021-38102
IPPP82.FLT in Corel Presentations 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to access unauthorized system memory in the context of the curr... Read more
Affected Products : presentations_2020- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-0420
An information disclosure vulnerability in AOSP Mail could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain acce... Read more
Affected Products : android- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0424
An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its permission levels. This issue is rated as Moderate because it is a general bypass for a user level defense ... Read more
Affected Products : android- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2021-0689
In RGB_to_BGR1_portable of SkSwizzler_opts.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploita... Read more
Affected Products : android- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0693
In openFile of HeapDumpProvider.java, there is a possible way to retrieve generated heap dumps from debuggable apps due to an unprotected provider. This could lead to local information disclosure with no additional execution privileges needed. User intera... Read more
Affected Products : android- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-25488
Lack of boundary checking of a buffer in recv_data() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read.... Read more
- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-29906
IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, 1.3, 1.4 and 1.5 could disclose sensitive information to a local user when it is configured to use an IBM Cloud API key to connect to cloud-based connectors. IBM X-Force ID: 207630.... Read more
- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-40498
A vulnerability has been identified in SAP SuccessFactors Mobile Application for Android - versions older than 2108, which allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service, which can lead ... Read more
Affected Products : successfactors_mobile- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-6832
Heap-based buffer overflow in the ff_audio_resample function in resample.c in libav before 11.4 allows remote attackers to cause a denial of service (crash) via vectors related to buffer resizing.... Read more
Affected Products : libav- Published: Feb. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2021-39345
The HAL WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/wp-hal.php file which allowed attackers with administrative user access to inject arbitrary w... Read more
Affected Products : hal- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-18672
An issue was discovered on Samsung mobile devices with L(5.0/5.1), M(6.0), and N(7.x) software. Because of incorrect exception handling for Intents, a local attacker can force a reboot within framework.jar. The Samsung ID is SVE-2017-8390 (May 2017).... Read more
Affected Products : android- Published: Apr. 07, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-39328
The Simple Job Board WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $job_board_privacy_policy_label variable echo'd out via the ~/admin/settings/class-simple-job-board-settings-privacy.php file which allo... Read more
Affected Products : simple_job_board- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024