Latest CVE Feed
-
5.5
MEDIUMCVE-2020-16855
<p>An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory. An attacker who successfully exploited the vulnerability could view o... Read more
Affected Products : office- Published: Sep. 11, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-1602
A potential security vulnerability has been identified in HP ThinPro 7.2 Service Pack 8 (SP8). The security vulnerability in SP8 is not remedied after upgrading from SP8 to Service Pack 9 (SP9). HP has released Service Pack 10 (SP10) to remediate the pote... Read more
- Published: Sep. 13, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-16355
The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for individual files.... Read more
Affected Products : beego- Published: Sep. 16, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-4197
member_portrait.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to modify or delete portraits of other users via unspecified vectors.... Read more
Affected Products : plone- Published: Mar. 11, 2014
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2017-2744
The vulnerability allows attacker to extract binaries into protected file system locations in HP Support Assistant before 12.7.26.1.... Read more
Affected Products : support_assistant- Published: Jan. 23, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-22552
An untrusted memory read vulnerability in Asylo versions up to 0.6.1 allows an untrusted attacker to pass a syscall number in MessageReader that is then used by sysno() and can bypass validation. This can allow the attacker to read memory from within the ... Read more
Affected Products : asylo- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-38164
SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attacker to invoke certain functions that... Read more
Affected Products : erp_financial_accounting- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2005-1880
everybuddy 0.4.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.... Read more
Affected Products : everybuddy- Published: Jun. 06, 2005
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2023-48341
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed... Read more
- Published: Jan. 18, 2024
- Modified: Jun. 20, 2025
-
5.5
MEDIUMCVE-2023-48344
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed... Read more
- Published: Jan. 18, 2024
- Modified: Jun. 20, 2025
-
5.5
MEDIUMCVE-2020-11005
The WindowsHello open source library (NuGet HaemmerElectronics.SeppPenner.WindowsHello), before version 1.0.4, has a vulnerability where encrypted data could potentially be decrypted without needing authentication. If the library is used to encrypt text a... Read more
Affected Products : windowshello- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-0692
A denial of service vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36725407.... Read more
Affected Products : android- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2024-0098
NVIDIA ChatRTX for Windows contains a vulnerability in the ChatRTX UI and backend, where a user can cause a clear-text transmission of sensitive information issue by data sniffing. A successful exploit of this vulnerability might lead to information discl... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2011-3518
Unspecified vulnerability in the Siebel Core - UIF Client component in Oracle Siebel CRM 8.0.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to User Interface.... Read more
Affected Products : siebel_crm- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
5.5
MEDIUMCVE-2008-7316
mm/filemap.c in the Linux kernel before 2.6.25 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers an iovec of zero length, followed by a page fault for an iovec of nonzero length.... Read more
Affected Products : linux_kernel- Published: May. 02, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2014-9485
Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1-5 might allow remote attackers to write to arbitrary files via a crafted entry in a ZIP archive.... Read more
Affected Products : minizip- Published: Jan. 16, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-5569
Unspecified vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component in Oracle Financial Services Applications 12.0.0 and 12.1.0 allows remote authenticated users to affect confidentiality and integrity via unknown vector... Read more
Affected Products : flexcube_enterprise_limits_and_collateral_management- Published: Oct. 25, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-5749
NetIQ Access Manager 4.1 before 4.1.2 HF 1 and 4.2 before 4.2.2 was parsing incoming SAML requests with external entity resolution enabled, which could lead to local file disclosure via an XML External Entity (XXE) attack.... Read more
Affected Products : access_manager- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-5927
IBM Tivoli Storage Manager for Space Management (aka Spectrum Protect for Space Management) 6.3.x before 6.3.2.6, 6.4.x before 6.4.3.3, and 7.1.x before 7.1.6, when certain dsmsetpw tracing is configured, allows local users to discover an encrypted passwo... Read more
Affected Products : tivoli_storage_manager_for_space_management- Published: Sep. 12, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-6236
The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg file.... Read more
Affected Products : lepton- Published: Feb. 02, 2017
- Modified: Apr. 20, 2025