Latest CVE Feed
-
5.5
MEDIUMCVE-2023-1645
A vulnerability was found in IObit Malware Fighter 9.4.0.776. It has been classified as problematic. This affects the function 0x8018E008 in the library IMFCameraProtect.sys of the component IOCTL Handler. The manipulation leads to denial of service. The ... Read more
Affected Products : malware_fighter- Published: Mar. 26, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-38532
A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Parasolid V35.1 (All versions < V35.1.171), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization... Read more
- Published: Aug. 08, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-39505
PDF-XChange Editor Net.HTTP.requests Exposed Dangerous Function Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is require... Read more
- Published: May. 03, 2024
- Modified: May. 19, 2025
-
5.5
MEDIUMCVE-2023-38454
In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges... Read more
- Published: Sep. 04, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-40076
In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti... Read more
Affected Products : android- Published: Dec. 04, 2023
- Modified: May. 29, 2025
-
5.5
MEDIUMCVE-2023-21029
In register of UidObserverController.java, there is a missing permission check. This could lead to local information disclosure of app usage with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A... Read more
Affected Products : android- Published: Mar. 24, 2023
- Modified: Feb. 25, 2025
-
5.5
MEDIUMCVE-2023-40435
This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 15. An app may be able to access App Store credentials.... Read more
Affected Products : xcode- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-21200
In on_remove_iso_data_path of btm_iso_impl.h, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo... Read more
Affected Products : android- Published: Jun. 28, 2023
- Modified: Dec. 04, 2024
-
5.5
MEDIUMCVE-2023-21319
In UsageStatsService, there is a possible way to read installed 3rd party apps due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e... Read more
Affected Products : android- Published: Oct. 30, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-21285
In setMetadata of MediaSessionRecord.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e... Read more
Affected Products : android- Published: Aug. 14, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-41010
Insecure Permissions vulnerability in Sichuan Tianyi Kanghe Communication Co., Ltd China Telecom Tianyi Home Gateway v.TEWA-700G allows a local attacker to obtain sensitive information via the default password parameter.... Read more
- Published: Sep. 14, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-41078
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14. An app may be able to bypass certain Privacy preferences.... Read more
Affected Products : macos- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-41316
Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails with HTML injected code to the victims. Registered users can inject HTML into unsanitized emails from the Tolgee instance to other users.... Read more
Affected Products : tolgee- Published: Sep. 07, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-22409
An Unchecked Input for Loop Condition vulnerability in a NAT library of Juniper Networks Junos OS allows a local authenticated attacker with low privileges to cause a Denial of Service (DoS). When an inconsistent "deterministic NAT" configuration is prese... Read more
- Published: Jan. 13, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-42109
PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to expl... Read more
- Published: May. 03, 2024
- Modified: May. 16, 2025
-
5.5
MEDIUMCVE-2023-23437
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak ... Read more
Affected Products : vmall- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-23021
The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission bits set to 644.... Read more
Affected Products : nginx_controller- Published: Jun. 01, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-20706
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767860; Issue ID... Read more
- Published: May. 15, 2023
- Modified: Jan. 24, 2025
-
5.5
MEDIUMCVE-2023-20996
In multiple locations, there is a possible way to trigger a persistent reboot loop due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product:... Read more
Affected Products : android- Published: Mar. 24, 2023
- Modified: Feb. 25, 2025
-
5.5
MEDIUMCVE-2023-21243
In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file with no limits due to a buffer overflow. This could lead to local denial of service with no additional execution privileges needed. Us... Read more
Affected Products : android- Published: Jul. 13, 2023
- Modified: Nov. 21, 2024