Latest CVE Feed
-
5.5
MEDIUMCVE-2020-12288
Protection mechanism failure in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.... Read more
Affected Products : jhl6240_thunderbolt_3_firmware jhl6340_thunderbolt_3_firmware jhl6540_thunderbolt_3_firmware jhl7040_thunderbolt_3_retimer_firmware jhl7340_thunderbolt_3_firmware jhl7440_thunderbolt_3_firmware jhl7540_thunderbolt_3_firmware jhl8010r_usb_retimer_firmware dsl5320_thunderbolt_2_firmware dsl5520_thunderbolt_2_firmware +16 more products- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-20348
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other... Read more
Affected Products : rational_doors_next_generation rational_collaborative_lifecycle_management rational_engineering_lifecycle_manager rational_quality_manager collaborative_lifecycle_management engineering_lifecycle_management engineering_test_management engineering_lifecycle_optimization engineering_lifecycle_optimization_-_engineering_insights engineering_lifecycle_optimization_-_publishing +1 more products- Published: Jun. 02, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-34529
WASM3 v0.5.0 was discovered to contain a segmentation fault via the component Compile_Memory_CopyFill.... Read more
Affected Products : wasm3- Published: Jul. 27, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-35081
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_read_header at /src/png2swf.c.... Read more
Affected Products : swftools- Published: Oct. 13, 2022
- Modified: May. 15, 2025
-
5.5
MEDIUMCVE-2022-35719
IBM MQ Internet Pass-Thru 2.1, 9.2 LTS and 9.2 CD stores potentially sensitive information in trace files that could be read by a local user.... Read more
Affected Products : mq_internet_pass-thru- Published: Nov. 14, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-36152
tifig v0.2.2 was discovered to contain a memory leak via operator new[](unsigned long) at /asan/asan_new_delete.cpp.... Read more
Affected Products : tifig- Published: Aug. 16, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-36153
tifig v0.2.2 was discovered to contain a segmentation violation via std::vector<unsigned int, std::allocator<unsigned int> >::size() const at /bits/stl_vector.h.... Read more
Affected Products : tifig- Published: Aug. 16, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-12911
A denial of service vulnerability exists in the D3DKMTCreateAllocation handler functionality of AMD ATIKMDAG.SYS (e.g. version 26.20.15029.27017). A specially crafted D3DKMTCreateAllocation API request can cause an out-of-bounds read and denial of service... Read more
Affected Products : atikmdag.sys- Published: Oct. 13, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-27652
An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of service via the update_info field of the _default_.xml file.... Read more
Affected Products : super_clean- Published: Apr. 20, 2023
- Modified: Feb. 05, 2025
-
5.5
MEDIUMCVE-2022-42383
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- Published: Jan. 26, 2023
- Modified: Nov. 27, 2024
-
5.5
MEDIUMCVE-2014-2986
The vgic_distr_mmio_write function in the virtual guest interrupt controller (GIC) distributor (arch/arm/vgic.c) in Xen 4.4.x, when running on an ARM system, allows local guest users to cause a denial of service (NULL pointer dereference and host crash) v... Read more
Affected Products : xen- Published: Apr. 28, 2014
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2022-44430
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.... Read more
- Published: Jan. 04, 2023
- Modified: Apr. 10, 2025
-
5.5
MEDIUMCVE-2021-42331
The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers can access and edit other users’ tutorial schedule by crafting URL parameters.... Read more
Affected Products : xinhe_teaching_platform_system- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-40103
Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formSetAutoPing function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.... Read more
- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
5.5
MEDIUMCVE-2022-34110
An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to download arbitrary files regardless of file type or size.... Read more
Affected Products : micro-star_international_feature_navigator- Published: Sep. 12, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-30730
Implicit intent hijacking vulnerability in Camera prior to versions 11.0.16.43 in Android 11, 12.1.00.30, 12.0.07.53, 12.1.03.10 in Android 12, and 13.0.01.43, 13.1.00.83 in Android 13 allows local attacker to access specific file.... Read more
- Published: Sep. 06, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-41166
Due to lack of proper memory management, when a victim opens manipulated Wavefront Object (.obj, ObjTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible for the application to crash and become... Read more
Affected Products : 3d_visual_enterprise_author- Published: Oct. 11, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-31920
Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the vm_loop at jerry-core/vm/vm.c.... Read more
Affected Products : jerryscript- Published: May. 12, 2023
- Modified: Jan. 24, 2025
-
5.5
MEDIUMCVE-2020-24700
OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.... Read more
Affected Products : open-xchange_appsuite- Published: Jan. 12, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-47343
In engineermode services, there is a missing permission check. This could lead to local denial of service in engineermode services.... Read more
- Published: Feb. 12, 2023
- Modified: Mar. 26, 2025