Latest CVE Feed
-
5.5
MEDIUMCVE-2022-42764
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
5.5
MEDIUMCVE-2023-47081
Adobe Substance 3D Stager versions 2.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of t... Read more
- Published: Dec. 13, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-48636
Adobe Substance 3D Designer versions 13.0.0 (and earlier) and 13.1.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations s... Read more
Affected Products : substance_3d_designer- Published: Dec. 13, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-6762
A vulnerability, which was classified as critical, was found in Thecosy IceCMS 2.0.1. Affected is an unknown function of the file /article/DelectArticleById/ of the component Article Handler. The manipulation leads to permission issues. It is possible to ... Read more
Affected Products : icecms- Published: Dec. 13, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-42772
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.... Read more
- Published: Dec. 06, 2022
- Modified: Apr. 23, 2025
-
5.5
MEDIUMCVE-2023-42698
In omacp service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed... Read more
- Published: Dec. 04, 2023
- Modified: May. 29, 2025
-
5.5
MEDIUMCVE-2023-42701
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed... Read more
- Published: Dec. 04, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-42713
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed... Read more
- Published: Dec. 04, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-42742
In sysui, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed... Read more
- Published: Dec. 04, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-23438
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions ... Read more
- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-23439
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. ... Read more
- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-51432
Some Honor products are affected by out of bounds read vulnerability, successful exploitation could cause information leak. ... Read more
Affected Products : magic_ui- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-38022
An issue was discovered in Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform before 3.29 for Intel SGX. Insufficient pointer validation allows a local attacker to access unauthorized information. This relates to strlen and sgx_is_within_use... Read more
Affected Products : confidential_computing_manager- Published: Dec. 30, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-47857
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia camera crash through modify a released pointer.... Read more
- Published: Jan. 02, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-20805
Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.... Read more
- Published: Jan. 04, 2024
- Modified: Jun. 03, 2025
-
5.5
MEDIUMCVE-2012-0433
The install-chef-suse.sh script shipped with crowbar before 2012-10-02 is creating files containing confidential data with insecure permissions, allowing local users to read confidential data.... Read more
Affected Products : crowbar- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-40411
This issue was addressed with improved data protection. This issue is fixed in macOS Sonoma 14. An app may be able to access user-sensitive data.... Read more
Affected Products : macos- Published: Jan. 10, 2024
- Modified: Jun. 17, 2025
-
5.5
MEDIUMCVE-2023-42929
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access protected user data.... Read more
Affected Products : macos- Published: Jan. 10, 2024
- Modified: Jan. 27, 2025
-
5.5
MEDIUMCVE-2023-50920
An issue was discovered on GL.iNet devices before version 4.5.0. They assign the same session ID after each user reboot, allowing attackers to share session identifiers between different sessions and bypass authentication or access control measures. Attac... Read more
Affected Products : gl-mt3000_firmware gl-mt1300_firmware gl-mt300n-v2_firmware gl-ar750s_firmware gl-ar750_firmware gl-ar300m_firmware gl-b1300_firmware gl-mt6000_firmware gl-a1300_firmware gl-ax1800_firmware +14 more products- Published: Jan. 12, 2024
- Modified: Jun. 17, 2025
-
5.5
MEDIUMCVE-2018-12418
Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulnerability due to an infinite loop when handling corrupt RAR files.... Read more
Affected Products : junrar- Published: Jun. 14, 2018
- Modified: Nov. 21, 2024