Latest CVE Feed
-
5.5
MEDIUMCVE-2023-29735
An issue found in edjing Mix v.7.09.01 for Android allows a local attacker to cause a denial of service via the database files.... Read more
Affected Products : edjing_mix- Published: May. 30, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-33716
mp4v2 v2.1.3 was discovered to contain a memory leak via the class MP4StringProperty at mp4property.cpp.... Read more
Affected Products : mp4v2- Published: Jun. 01, 2023
- Modified: Jan. 09, 2025
-
5.5
MEDIUMCVE-2023-33717
mp4v2 v2.1.3 was discovered to contain a memory leak when a method calling MP4File::ReadBytes() had allocated memory but did not catch exceptions thrown by ReadBytes()... Read more
Affected Products : mp4v2- Published: Jun. 02, 2023
- Modified: Jan. 08, 2025
-
5.5
MEDIUMCVE-2022-48446
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.... Read more
- Published: Jun. 06, 2023
- Modified: Jan. 08, 2025
-
5.5
MEDIUMCVE-2017-15517
AltaVault OST Plug-in versions prior to 1.2.2 may allow attackers to obtain sensitive information via unspecified vectors. All users are urged to move to a fixed version and change passwords used by Veritas NetBackup to access the OST shares on the NetApp... Read more
Affected Products : altavault_ost_plug-in- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2022-47484
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.... Read more
- Published: Mar. 10, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-48378
In engineermode service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.... Read more
- Published: May. 09, 2023
- Modified: Jan. 28, 2025
-
5.5
MEDIUMCVE-2020-36709
The Page Builder: KingComposer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via via shortcode in versions before 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to i... Read more
Affected Products : page_builder_kingcomposer- Published: Jun. 07, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-33283
Marval MSM through 14.19.0.12476 uses a static encryption key for secrets. An attacker that gains access to encrypted secrets can decrypt them by using this key.... Read more
Affected Products : msm- Published: Jun. 07, 2023
- Modified: Jan. 07, 2025
-
5.5
MEDIUMCVE-2023-2767
The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.19.1 due to insufficient input sanitization and output escaping. This makes ... Read more
- Published: Jun. 09, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-29759
An issue found in FlightAware v.5.8.0 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the database files.... Read more
Affected Products : flightaware- Published: Jun. 09, 2023
- Modified: Jan. 06, 2025
-
5.5
MEDIUMCVE-2023-29767
An issue found in CrossX v.1.15.3 for Android allows a local attacker to cause a persistent denial of service via the database files.... Read more
Affected Products : crossx- Published: Jun. 09, 2023
- Modified: Jan. 06, 2025
-
5.5
MEDIUMCVE-2023-29756
An issue found in Twilight v.13.3 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the SharedPreference files.... Read more
Affected Products : twilight- Published: Jun. 09, 2023
- Modified: Jan. 06, 2025
-
5.5
MEDIUMCVE-2023-21137
In several methods of JobStore.java, uncaught exceptions in job map parsing could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-... Read more
Affected Products : android- Published: Jun. 15, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-17113
ntguard_x64.sys 0.18780.0.0 in IKARUS anti.virus 2.16.15 has a NULL pointer dereference via a 0x830000c4 DeviceIoControl request.... Read more
- Published: Dec. 04, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-1266
IBM Security Guardium 10.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 124741.... Read more
Affected Products : security_guardium- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-1595
IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM X-Force ID: 132549.... Read more
Affected Products : security_guardium- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2021-26354
Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity. ... Read more
Affected Products : epyc_7h12_firmware epyc_7f72_firmware epyc_7f52_firmware epyc_7f32_firmware epyc_7742_firmware epyc_7702p_firmware epyc_7702_firmware epyc_7662_firmware epyc_7642_firmware epyc_7552_firmware +294 more products- Published: May. 09, 2023
- Modified: Jan. 28, 2025
-
5.5
MEDIUMCVE-2017-1000455
GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creation of setuid executables in "the store", violating a fundamental security assumption of GNU Guix.... Read more
Affected Products : guixsd- Published: Jan. 02, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-30866
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.... Read more
- Published: Jun. 06, 2023
- Modified: Jan. 08, 2025