Latest CVE Feed
-
5.5
MEDIUMCVE-2018-11971
Interrupt exit code flow may undermine access control policy set forth by secure world can lead to potential secure asset leakage in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Ind... Read more
Affected Products : sd_8cx_firmware sdm660_firmware qcs605_firmware mdm9650_firmware mdm9206_firmware mdm9607_firmware sda660_firmware sd_636_firmware mdm9655_firmware sdm630_firmware +32 more products- Published: Apr. 04, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-42699
In omacp service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed... Read more
- Published: Dec. 04, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-42703
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed... Read more
- Published: Dec. 04, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-42705
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed... Read more
- Published: Dec. 04, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-11463
A memory leak in archive_read_format_zip_cleanup in archive_read_support_format_zip.c in libarchive 3.3.4-dev allows remote attackers to cause a denial of service via a crafted ZIP file because of a HAVE_LZMA_H typo. NOTE: this only affects users who down... Read more
Affected Products : libarchive- Published: Apr. 23, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-13811
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All Versions < V15.1). Password hashes with insufficient computational effort could allow an attacker to access to a project file and reconstruct passwords. The vulnerability could be exp... Read more
Affected Products : simatic_step_7_\(tia_portal\)- Published: Dec. 13, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-11686
Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically sensitive parameters (such as data encryption keys) to remain on the drive media after their intended eras... Read more
Affected Products : sandisk_x600_sd9tb8w-128g_firmware sandisk_x600_sd9tb8w-256g_firmware sandisk_x600_sd9tb8w-512g_firmware sandisk_x600_sd9tb8w-1t00_firmware sandisk_x600_sd9tb8w-2t00_firmware sandisk_x600_sd9tn8w-128g_firmware sandisk_x600_sd9tn8w-256g_firmware sandisk_x600_sd9tn8w-512g_firmware sandisk_x600_sd9tn8w-1t00_firmware sandisk_x600_sd9tn8w-2t00_firmware +108 more products- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-14545
There exists one invalid memory read bug in AP4_SampleDescription::GetType() in Ap4SampleDescription.h in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executabl... Read more
Affected Products : bento4- Published: Jul. 23, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-12477
Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcast fake video without any authentication via a /remote/media_control?action=setUri&uri= URI.... Read more
- Published: Jun. 07, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-11653
Remote Access Control Bypass in Micro Focus Content Manager. versions 9.1, 9.2, 9.3. The vulnerability could be exploited to manipulate data stored during another user’s CheckIn request.... Read more
Affected Products : content_manager- Published: Aug. 07, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-12919
On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the local network has unauthenticated access to the internal SD card via the HTTP service on port 8000. The HTTP web server on the camera allows anyone to view or downl... Read more
- Published: Jun. 20, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-2460
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted application, related to IGraphicBu... Read more
Affected Products : android- Published: May. 09, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2018-1677
IBM DataPower Gateways 7.1, 7.2, 7.5, 7.5.1, 7.5.2, 7.6, and 7.7 and IBM MQ Appliance are vulnerable to a denial of service, caused by the improper handling of full file system. A local attacker could exploit this vulnerability to cause a denial of servic... Read more
Affected Products : datapower_gateway- Published: Dec. 20, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-1002205
DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.... Read more
Affected Products : dotnetzip.semverd- Published: Jul. 25, 2018
- Modified: May. 06, 2025
-
5.5
MEDIUMCVE-2019-14225
OX App Suite 7.10.1 and 7.10.2 allows SSRF.... Read more
Affected Products : open-xchange_appsuite- Published: Oct. 14, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-14337
An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is an ability to escape to a shell in the restricted command line interface, as demonstrated by the `/bin/sh -c wget` sequence.... Read more
- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-14362
Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated attackers to replace a file on the server via the getAttachmentDirectoryForNewAttachment inpKey value.... Read more
Affected Products : openbravo_erp- Published: Jul. 28, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11275
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, when flashing image using FastbootLib if size is not divisible by block size, information leak occurs.... Read more
Affected Products : android- Published: Sep. 18, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-42633
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed... Read more
- Published: Nov. 01, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-42640
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed... Read more
- Published: Nov. 01, 2023
- Modified: Nov. 21, 2024