Latest CVE Feed
-
5.5
MEDIUMCVE-2016-8306
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 12.0.1, 12.0.2,12.0.4,12.1.0 and 12.3.0. Easily exploitable vulnerability allows low... Read more
Affected Products : flexcube_investor_servicing- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2023-4333
Broadcom RAID Controller web interface doesn’t enforce SSL cipher ordering by server... Read more
- Published: Aug. 15, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-23205
An issue was discovered in lib60870 v2.3.2. There is a memory leak in lib60870/lib60870-C/examples/multi_client_server/multi_client_server.c.... Read more
Affected Products : lib60870- Published: Feb. 24, 2023
- Modified: Mar. 12, 2025
-
5.5
MEDIUMCVE-2023-29471
Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.... Read more
Affected Products : alpakka_kafka- Published: Apr. 27, 2023
- Modified: Jan. 31, 2025
-
5.5
MEDIUMCVE-2021-34560
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least on... Read more
- Published: Aug. 31, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11590
Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via an integer overflow during syntax parsing. This was addressed by fixing stack size detection on Linux in jsutils.c.... Read more
Affected Products : espruino- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-3620
u'Lack of check of integer overflow while doing a round up operation for data read from shared memory for G-link SMEM transport can lead to corruption and potential information leak' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdra... Read more
Affected Products : sa6155p_firmware ipq8074_firmware qca8081_firmware sdx55_firmware sdm660_firmware sm8150_firmware sm8250_firmware sxr2130_firmware msm8996au_firmware apq8096au_firmware +116 more products- Published: Sep. 08, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-27548
HCL Launch stores user credentials in plain clear text which can be read by a local user.... Read more
Affected Products : hcl_launch- Published: Jul. 06, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-4274
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to access data and perform unauthorized actions due to inadequate permission checks. IBM X-ForceID: 175980.... Read more
- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-20091
An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when called from AP4_DecoderConfigDescriptor::GetDecoderSpecificInfoDescriptor in Ap4DecoderConfigDescriptor.cpp.... Read more
Affected Products : bento4- Published: Dec. 30, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-9245
HUAWEI P30 versions Versions earlier than 10.1.0.160(C00E160R2P11);HUAWEI P30 Pro versions Versions earlier than 10.1.0.160(C00E160R2P8) have a denial of service vulnerability. Certain system configuration can be modified because of improper authorization... Read more
- Published: Aug. 10, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-9264
ESET Archive Support Module before 1296 allows virus-detection bypass via a crafted Compression Information Field in a ZIP archive. This affects versions before 1294 of Smart Security Premium, Internet Security, NOD32 Antivirus, Cyber Security Pro (macOS)... Read more
Affected Products : nod32_antivirus smart_security internet_security cyber_security mobile_security smart_tv_security- Published: Feb. 18, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-33437
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There are memory leaks in frozen_cb() in mjs.c.... Read more
Affected Products : mjs- Published: Jul. 26, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-21818
NVIDIA License System contains a vulnerability in the installation scripts for the DLS virtual appliance, where a user on a network after signing in to the portal can access other users’ credentials, allowing them to gain escalated privileges, resulting i... Read more
Affected Products : license_system- Published: Feb. 15, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-32414
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_vmcode_interpreter at src/njs_vmcode.c.... Read more
Affected Products : njs- Published: Jun. 21, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-29569
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via ffi_cb_impl_wpwwwww at src/mjs_ffi.c. This vulnerability can lead to a Denial of Service (DoS).... Read more
Affected Products : mjs- Published: Apr. 14, 2023
- Modified: Feb. 06, 2025
-
5.5
MEDIUMCVE-2023-40715
A cleartext storage of sensitive information vulnerability [CWE-312] in FortiTester 2.3.0 through 7.2.3 may allow an attacker with access to the DB contents to retrieve the plaintext password of external servers configured in the device.... Read more
Affected Products : fortitester- Published: Sep. 13, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-5748
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology SSL VPN Client before 1.4.7-0687 allows local users to conduct denial-of-service attacks via unspecified vectors.... Read more
Affected Products : ssl_vpn_client- Published: Nov. 07, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-9982
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Apple Music 3.4.0 for Android. A malicious application may be able to leak a user's credentials.... Read more
Affected Products : music- Published: Oct. 27, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-12219
Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.63... Read more
Affected Products : graphics_driver- Published: Mar. 14, 2019
- Modified: Nov. 21, 2024