Latest CVE Feed
-
5.5
MEDIUMCVE-2022-34282
A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application is vulnerable to an out of bounds read past the end of an allocated buffer when parsing PCB files. An attacker could leverage this vulnerability to l... Read more
Affected Products : pads_viewer- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-34287
A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains a stack corruption vulnerability while parsing PCB files. An attacker could leverage this vulnerability to leak information in the context o... Read more
Affected Products : pads_viewer- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-31597
Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does not perform necessary authorization checks for a low privileged authenticated user over the network, result... Read more
- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-35171
When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format de... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20219
In multiple functions of StorageManagerService.java and UserManagerService.java, there is a possible way to leave user's directories unencrypted due to a logic error in the code. This could lead to local information disclosure with no additional execution... Read more
Affected Products : android- Published: Jul. 13, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20225
In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interacti... Read more
Affected Products : android- Published: Jul. 13, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20227
In USB driver, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android k... Read more
Affected Products : android- Published: Jul. 13, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20230
In choosePrivateKeyAlias of KeyChain.java, there is a possible access to the user's certificate due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed fo... Read more
Affected Products : android- Published: Jul. 13, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-1662
In convert2rhel, there's an ansible playbook named ansible/run-convert2rhel.yml which passes the Red Hat Subscription Manager user password via the CLI to convert2rhel. This could allow unauthorized local users to view the password via the process list wh... Read more
Affected Products : convert2rhel- Published: Jul. 14, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-34637
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a implements an incorrect exception type when an illegal virtual address is loaded.... Read more
Affected Products : cva6- Published: Jul. 18, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-20665
In devinfo, there is a possible information disclosure due to a missing SELinux policy. This could lead to local information disclosure of device identifier with no additional execution privileges needed. User interaction is not needed for exploitation. P... Read more
- Published: May. 05, 2025
- Modified: May. 12, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2022-22424
IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to incorrect file permissions. IBM X-Force ID: 223597.... Read more
- Published: Jul. 20, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-33456
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in hash() in modules/preprocs/nasm/nasm-pp.c.... Read more
Affected Products : yasm- Published: Jul. 26, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-33467
An issue was discovered in yasm version 1.3.0. There is a use-after-free in pp_getline() in modules/preprocs/nasm/nasm-pp.c.... Read more
Affected Products : yasm- Published: Jul. 26, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-29960
Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES with hardcoded cryptographic keys is used for protection of certain system credentials, engineering files... Read more
Affected Products : openbsi- Published: Jul. 26, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-20975
Improper Export of Android Application Components in AODService prior to version 8.8.28.12 allows local attackers to launch arbitrary activity with systemui privilege.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2022-29071
This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vulnera... Read more
Affected Products : cloudvision_portal- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUM- Published: Aug. 09, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20289
In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. U... Read more
Affected Products : android- Published: Aug. 12, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20324
In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User int... Read more
Affected Products : android- Published: Aug. 12, 2022
- Modified: Nov. 21, 2024