Latest CVE Feed
-
5.5
MEDIUMCVE-2023-28387
"NewsPicks" App for Android versions 10.4.5 and earlier and "NewsPicks" App for iOS versions 10.4.2 and earlier use hard-coded credentials, which may allow a local attacker to analyze data in the app and to obtain API key for an external service.... Read more
Affected Products : newspicks- Published: Jun. 30, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-29950
swfrender v0.9.2 was discovered to contain a heap buffer overflow in the function enumerateUsedIDs_fillstyle at modules/swftools.c... Read more
Affected Products : swftools- Published: Apr. 27, 2023
- Modified: Jan. 31, 2025
-
5.5
MEDIUMCVE-2023-4891
A potential use-after-free vulnerability was reported in the Lenovo View driver that could result in denial of service. ... Read more
- Published: Nov. 08, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-6939
Some Honor products are affected by type confusion vulnerability, successful exploitation could cause denial of service.... Read more
Affected Products : magic_ui- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-50570
An issue in the component IPAddressBitsDivision of IPAddress v5.1.0 leads to an infinite loop. This is disputed because an infinite loop occurs only for cases in which the developer supplies invalid arguments. The product is not intended to always halt fo... Read more
Affected Products : ipaddress- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0636
A denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a system crash.... Read more
Affected Products : thin_installer- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-1849
Session Fixation in GitHub repository filegator/filegator prior to 7.8.0.... Read more
Affected Products : filegator- Published: May. 24, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-45933
wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow (8 bytes) in MqttDecode_Publish (called from MqttClient_DecodePacket and MqttClient_HandlePacket).... Read more
Affected Products : wolfmqtt- Published: Jan. 01, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-34625
Out-of-bounds read in applying connection point in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.... Read more
Affected Products : notes- Published: Aug. 07, 2024
- Modified: Aug. 09, 2024
-
5.5
MEDIUMCVE-2024-34644
Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulnerability.... Read more
- Published: Sep. 04, 2024
- Modified: Sep. 05, 2024
-
5.5
MEDIUMCVE-2021-46168
Spin v6.5.1 was discovered to contain an out-of-bounds write in lex() at spinlex.c.... Read more
Affected Products : spin- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-46333
Moddable SDK v11.5.0 was discovered to contain an invalid memory access vulnerability via the component __asan_memmove.... Read more
Affected Products : moddable_sdk- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-46344
There is an Assertion 'flags & PARSER_PATTERN_HAS_REST_ELEMENT' failed at /jerry-core/parser/js/js-parser-expr.c in JerryScript 3.0.0.... Read more
Affected Products : jerryscript- Published: Jan. 20, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-24635
The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscriber) to call them and 1) Get and sea... Read more
Affected Products : visual_link_preview- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-11123
u'information disclosure in gatekeeper trustzone implementation as the throttling mechanism to prevent brute force attempts at getting user`s lock-screen password can be bypassed by performing the standard gatekeeper operations.' in Snapdragon Auto, Snapd... Read more
Affected Products : sa6145p_firmware sa6150p_firmware sa6155p_firmware sa8150p_firmware sa8155p_firmware sa8195p_firmware sdx55m_firmware qcm4290_firmware qcs4290_firmware qsm8250_firmware +220 more products- Published: Nov. 12, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-46480
Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiValueObjDelete in src/jsiEval.c. This vulnerability can lead to a Denial of Service (DoS).... Read more
Affected Products : jsish- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-30930
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.... Read more
- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-30941
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.... Read more
- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-6105
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the ex... Read more
- Published: Nov. 15, 2023
- Modified: Feb. 13, 2025
-
5.5
MEDIUMCVE-2024-37137
Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky Implementation vulnerability. A local privileged attacker could potentially exploit this vulnerability, leading to privileged information disclosure.... Read more
Affected Products : cloudlink- Published: Jun. 28, 2024
- Modified: Feb. 03, 2025