Latest CVE Feed
-
5.5
MEDIUMCVE-2019-10523
Target specific data is being sent to remote server and leads to information exposure in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables in APQ8009, APQ8053, ... Read more
Affected Products : qca6574au_firmware sm8150_firmware sm8250_firmware sxr2130_firmware msm8996au_firmware apq8096au_firmware qcs605_firmware apq8009_firmware msm8909w_firmware sdm429w_firmware +36 more products- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-41994
A logic issue was addressed with improved checks This issue is fixed in macOS Sonoma 14. A camera extension may be able to access the camera view from apps other than the app for which it was granted permission.... Read more
Affected Products : macos- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
5.5
MEDIUMCVE-2024-32914
In tpu_get_int_state of tpu.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Jun. 13, 2024
- Modified: Jul. 24, 2025
-
5.5
MEDIUMCVE-2015-0149
The developer portal in IBM API Management 3.0 before 3.0.4.1 does not properly restrict access to the public and private APIs, which allows remote authenticated users to obtain sensitive information or modify data via unspecified API calls.... Read more
Affected Products : api_management- Published: Mar. 18, 2015
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2023-42132
FD Application Apr. 2022 Edition (Version 9.01) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.... Read more
Affected Products : fd_application- Published: Oct. 02, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-42639
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed... Read more
- Published: Nov. 01, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-47452
In gnss driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.... Read more
- Published: Feb. 12, 2023
- Modified: Mar. 26, 2025
-
5.5
MEDIUMCVE-2024-4976
Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference.... Read more
Affected Products : xpdf- Published: May. 15, 2024
- Modified: Jan. 29, 2025
-
5.5
MEDIUMCVE-2024-20809
Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.... Read more
Affected Products : nearby_device_scanning- Published: Jan. 04, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-20825
Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.... Read more
Affected Products : galaxy_store- Published: Feb. 06, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0641
In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. Use... Read more
Affected Products : android- Published: Aug. 17, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0651
In loadLabel of PackageItemInfo.java, there is a possible way to DoS a device by having a long label in an app due to incorrect input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction i... Read more
Affected Products : android- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0562
In RasterIntraUpdate of motion_est.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio... Read more
Affected Products : android- Published: Jun. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-39504
PDF-XChange Editor OXPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exp... Read more
- Published: May. 03, 2024
- Modified: May. 19, 2025
-
5.5
MEDIUMCVE-2020-0425
There is a possible way to view notifications even when the "Lockdown" feature is on. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:... Read more
Affected Products : android- Published: Sep. 17, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-48504
The issue was addressed with improved handling of caches. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.... Read more
Affected Products : macos- Published: Jan. 10, 2024
- Modified: Jun. 03, 2025
-
5.5
MEDIUMCVE-2020-0437
In CellBroadcastReceiver's intent handlers, there is a possible denial of service due to a missing permission check. This could lead to local denial of service of emergency alerts with no additional execution privileges needed. User interaction is not nee... Read more
Affected Products : android- Published: Nov. 10, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-0496
In CPDF_RenderStatus::LoadSMask of cpdf_renderstatus.cpp, there is a possible memory corruption due to a use-after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp... Read more
Affected Products : android- Published: Dec. 15, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-40098
In mOnDone of NotificationConversationInfo.java, there is a possible way to access app notification data of another user due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User... Read more
Affected Products : android- Published: Dec. 04, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-45243
Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 35739.... Read more
- Published: Oct. 05, 2023
- Modified: Nov. 21, 2024