Latest CVE Feed
-
5.5
MEDIUMCVE-2022-20206
In setPackageOrComponentEnabled of NotificationManagerService.java, there is a missing permission check. This could lead to local information disclosure about enabled notification listeners with User execution privileges needed. User interaction is not ne... Read more
Affected Products : android- Published: Jun. 15, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20296
In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitatio... Read more
Affected Products : android- Published: Aug. 12, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20293
In LauncherApps, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User ... Read more
Affected Products : android- Published: Aug. 12, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-32014
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js.... Read more
- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20303
In ContentService, there is a possible way to determine if an account is on the device without GET_ACCOUNTS permission due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interacti... Read more
Affected Products : android- Published: Aug. 12, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20590
In valid_va_sec_mfc_check of drm_access_control.c, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed ... Read more
Affected Products : android- Published: Dec. 16, 2022
- Modified: Apr. 18, 2025
-
5.5
MEDIUMCVE-2021-27455
Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to disclose information.... Read more
Affected Products : dopsoft- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-33659
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is cau... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-21764
In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: AL... Read more
- Published: Jul. 06, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-34733
A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, local attacker to access sensitive information stored on the underlying file system of an affected system. This vul... Read more
- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-29567
TensorFlow is an end-to-end open source platform for machine learning. Due to lack of validation in `tf.raw_ops.SparseDenseCwiseMul`, an attacker can trigger denial of service via `CHECK`-fails or accesses to outside the bounds of heap allocated data. Sin... Read more
Affected Products : tensorflow- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-30219
samurai 1.2 has a NULL pointer dereference in printstatus() function in build.c via a crafted build file.... Read more
Affected Products : samurai- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20263
In ActivityManager, there is a way to read process state for other users due to a missing permission check. This could lead to local information disclosure of app usage with User execution privileges needed. User interaction is not needed for exploitation... Read more
Affected Products : android- Published: Aug. 12, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-23546
In version 2.9.0.beta14 of Discourse, an open-source discussion platform, maliciously embedded urls can leak an admin's digest of recent topics, possibly exposing private information. A patch is available for version 2.9.0.beta15. There are no known worka... Read more
Affected Products : discourse- Published: Jan. 05, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-25030
In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation function prior to storage. Popular hashing algorithms based on the Merkle-Damgardconstruction (such as MD5 and SHA-1) alon... Read more
- Published: May. 26, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-31539
Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.password file. A regular local user is able to read usernames and passwords.... Read more
Affected Products : streaming_engine- Published: Apr. 23, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-1801
There is an improper authentication vulnerability in several smartphones. Certain function interface in the system does not sufficiently validate the caller's identity in certain share scenario, successful exploit could cause information disclosure. Affec... Read more
- Published: Apr. 10, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-33599
A vulnerability affecting F-Secure Antivirus engine was discovered whereby scanning WIM archive file can lead to denial-of-service (infinite loop and freezes AV engine scanner). The vulnerability can be exploit remotely by an attacker. A successful attack... Read more
Affected Products : macos windows cloud_protection_for_salesforce linux_security elements_endpoint_protection atlant- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-48232
In FM service , there is a possible missing params check. This could lead to local denial of service in FM service .... Read more
- Published: May. 09, 2023
- Modified: Jan. 28, 2025
-
5.5
MEDIUMCVE-2021-39588
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_ReadABC() located in abc.c. It allows an attacker to cause Denial of Service.... Read more
Affected Products : swftools- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024