Latest CVE Feed
-
5.5
MEDIUMCVE-2018-17486
Lobby Track Desktop could allow a local attacker to bypass security restrictions, caused by an error in the find visitor function while in kiosk mode. By visiting the kiosk and selecting find visitor, an attacker could exploit this vulnerability to delete... Read more
Affected Products : lobby_track- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-0312
In Battery Saver, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Androi... Read more
Affected Products : android- Published: Sep. 17, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-46654
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a maliciou... Read more
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-16855
<p>An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory. An attacker who successfully exploited the vulnerability could view o... Read more
Affected Products : office- Published: Sep. 11, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-1602
A potential security vulnerability has been identified in HP ThinPro 7.2 Service Pack 8 (SP8). The security vulnerability in SP8 is not remedied after upgrading from SP8 to Service Pack 9 (SP9). HP has released Service Pack 10 (SP10) to remediate the pote... Read more
- Published: Sep. 13, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-16355
The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for individual files.... Read more
Affected Products : beego- Published: Sep. 16, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-4197
member_portrait.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to modify or delete portraits of other users via unspecified vectors.... Read more
Affected Products : plone- Published: Mar. 11, 2014
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2017-2744
The vulnerability allows attacker to extract binaries into protected file system locations in HP Support Assistant before 12.7.26.1.... Read more
Affected Products : support_assistant- Published: Jan. 23, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-22552
An untrusted memory read vulnerability in Asylo versions up to 0.6.1 allows an untrusted attacker to pass a syscall number in MessageReader that is then used by sysno() and can bypass validation. This can allow the attacker to read memory from within the ... Read more
Affected Products : asylo- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-38164
SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attacker to invoke certain functions that... Read more
Affected Products : erp_financial_accounting- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2005-1880
everybuddy 0.4.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.... Read more
Affected Products : everybuddy- Published: Jun. 06, 2005
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2023-48341
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed... Read more
- Published: Jan. 18, 2024
- Modified: Jun. 20, 2025
-
5.5
MEDIUMCVE-2023-48344
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with no additional execution privileges needed... Read more
- Published: Jan. 18, 2024
- Modified: Jun. 20, 2025
-
5.5
MEDIUMCVE-2020-11005
The WindowsHello open source library (NuGet HaemmerElectronics.SeppPenner.WindowsHello), before version 1.0.4, has a vulnerability where encrypted data could potentially be decrypted without needing authentication. If the library is used to encrypt text a... Read more
Affected Products : windowshello- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-0692
A denial of service vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36725407.... Read more
Affected Products : android- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2024-0098
NVIDIA ChatRTX for Windows contains a vulnerability in the ChatRTX UI and backend, where a user can cause a clear-text transmission of sensitive information issue by data sniffing. A successful exploit of this vulnerability might lead to information discl... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2011-3518
Unspecified vulnerability in the Siebel Core - UIF Client component in Oracle Siebel CRM 8.0.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to User Interface.... Read more
Affected Products : siebel_crm- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
5.5
MEDIUMCVE-2008-7316
mm/filemap.c in the Linux kernel before 2.6.25 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers an iovec of zero length, followed by a page fault for an iovec of nonzero length.... Read more
Affected Products : linux_kernel- Published: May. 02, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2014-9485
Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1-5 might allow remote attackers to write to arbitrary files via a crafted entry in a ZIP archive.... Read more
Affected Products : minizip- Published: Jan. 16, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-5569
Unspecified vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component in Oracle Financial Services Applications 12.0.0 and 12.1.0 allows remote authenticated users to affect confidentiality and integrity via unknown vector... Read more
Affected Products : flexcube_enterprise_limits_and_collateral_management- Published: Oct. 25, 2016
- Modified: Apr. 12, 2025