Latest CVE Feed
-
5.5
MEDIUMCVE-2019-11653
Remote Access Control Bypass in Micro Focus Content Manager. versions 9.1, 9.2, 9.3. The vulnerability could be exploited to manipulate data stored during another user’s CheckIn request.... Read more
Affected Products : content_manager- Published: Aug. 07, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-12919
On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the local network has unauthenticated access to the internal SD card via the HTTP service on port 8000. The HTTP web server on the camera allows anyone to view or downl... Read more
- Published: Jun. 20, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-2460
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted application, related to IGraphicBu... Read more
Affected Products : android- Published: May. 09, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2018-1677
IBM DataPower Gateways 7.1, 7.2, 7.5, 7.5.1, 7.5.2, 7.6, and 7.7 and IBM MQ Appliance are vulnerable to a denial of service, caused by the improper handling of full file system. A local attacker could exploit this vulnerability to cause a denial of servic... Read more
Affected Products : datapower_gateway- Published: Dec. 20, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-1002205
DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.... Read more
Affected Products : dotnetzip.semverd- Published: Jul. 25, 2018
- Modified: May. 06, 2025
-
5.5
MEDIUMCVE-2019-14225
OX App Suite 7.10.1 and 7.10.2 allows SSRF.... Read more
Affected Products : open-xchange_appsuite- Published: Oct. 14, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-14337
An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is an ability to escape to a shell in the restricted command line interface, as demonstrated by the `/bin/sh -c wget` sequence.... Read more
- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-14362
Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated attackers to replace a file on the server via the getAttachmentDirectoryForNewAttachment inpKey value.... Read more
Affected Products : openbravo_erp- Published: Jul. 28, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11275
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, when flashing image using FastbootLib if size is not divisible by block size, information leak occurs.... Read more
Affected Products : android- Published: Sep. 18, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-42633
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed... Read more
- Published: Nov. 01, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-42640
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed... Read more
- Published: Nov. 01, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11731
The libfsntfs_mft_entry_read_attributes function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this ... Read more
Affected Products : libfsntfs- Published: Jun. 19, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-15716
WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or were based on unsafe OS defaults.... Read more
Affected Products : wtf- Published: Aug. 28, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11951
Improper access control in core module lead XBL_LOADER performs the ZI region clear for QTEE instead of XBL_SEC in Snapdragon Mobile in version SD 845, SD 850.... Read more
- Published: Oct. 26, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-42642
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed... Read more
- Published: Nov. 01, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-13025
protected/apps/admin/controller/photoController.php in YXcms 1.4.7 allows remote attackers to delete arbitrary files via the index.php?r=admin/photo/delpic picname parameter.... Read more
Affected Products : yxcms- Published: Jun. 29, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-18301
In Small Cell SoC and Snapdragon (Automobile, Mobile, Wear) in version FSM9055, FSM9955, MDM9607, MDM9640, MDM9650, MSM8909W, SD 425, SD 427, SD 430, SD 435, SD 450, SD 617, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SDM630, SDM636, SDM660, SDX20... Read more
Affected Products : sdm660_firmware sd845_firmware mdm9650_firmware msm8909w_firmware sd625_firmware sd835_firmware sdx20_firmware mdm9607_firmware mdm9640_firmware sd820_firmware +36 more products- Published: Sep. 20, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-18324
Cryptographic key material leaked in debug messages - GERAN in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD... Read more
Affected Products : android sd_450_firmware sd_625_firmware sd_820_firmware sd_835_firmware sdx24_firmware mdm9650_firmware msm8909w_firmware mdm9206_firmware mdm9607_firmware +55 more products- Published: Jan. 03, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-1857
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00SPC100 have an information leakage vulnerability. Due to impr... Read more
Affected Products : nip6800_firmware secospace_usg6600_firmware usg9500_firmware usg9500 secospace_usg6600 nip6800- Published: Feb. 17, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-1369
An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'.... Read more
Affected Products : open_enclave_software_development_kit- Published: Oct. 10, 2019
- Modified: Nov. 21, 2024