Latest CVE Feed
-
5.5
MEDIUMCVE-2020-21533
fig2dev 3.2.7b contains a stack buffer overflow in the read_textobject function in read.c.... Read more
- Published: Sep. 16, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-18780
A Use After Free vulnerability in function new_Token in asm/preproc.c in nasm 2.14.02 allows attackers to cause a denial of service via crafted nasm command.... Read more
Affected Products : netwide_assembler- Published: Aug. 22, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-16150
Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0 may allow an attacker with access to the local storage or the configuration backup file to decrypt the se... Read more
Affected Products : forticlient- Published: Jun. 04, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-5995
The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "pages/cpu" printk call.... Read more
Affected Products : linux_kernel- Published: Aug. 07, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-10538
An issue was discovered in WavPack 5.1.0 and earlier for WAV input. Out-of-bounds writes can occur because ParseRiffHeaderConfig in riff.c does not validate the sizes of unknown chunks before attempting memory allocation, related to a lack of integer-over... Read more
- Published: Apr. 29, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-7173
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-0821
The LIST_POISON feature in include/linux/poison.h in the Linux kernel before 4.3, as used in Android 6.0.1 before 2016-03-01, does not properly consider the relationship to the mmap_min_addr value, which makes it easier for attackers to bypass a poison-po... Read more
- Published: Mar. 12, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2007-2437
The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to cause a denial of service (daemon crash) via crafted values to the (1) XRenderCompositeTrapezoids and (2) XRe... Read more
- Published: May. 02, 2007
- Modified: Apr. 09, 2025
-
5.5
MEDIUMCVE-2007-0269
Unspecified vulnerability in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to the Change Data Capture and sys.dbms_cdc_subscribe privileges, aka DB02.... Read more
Affected Products : database_server- Published: Jan. 17, 2007
- Modified: Apr. 09, 2025
-
5.5
MEDIUMCVE-2006-3719
Unspecified vulnerability in CORE: Repository for Oracle Enterprise Manager 9.0.1.0 and 9.2.0.1 has unknown impact and attack vectors, aka Oracle Vuln# EM01.... Read more
Affected Products : enterprise_manager- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2013-7195
PHPFox 3.7.3 and 3.7.4 allows remote authenticated users to bypass intended "Only Me" restrictions and "like" a publication via a request that specifies the ID for the publication.... Read more
Affected Products : phpfox- Published: Apr. 18, 2014
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2018-9867
In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the SonicWall Administrators user group attempt to download imported certificates. This vulnerability affected Soni... Read more
- Published: Feb. 19, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-11833
fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem.... Read more
- Published: May. 15, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-15731
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validating the output buffer address value from IOCtl 0x8000205B.... Read more
Affected Products : antimalware- Published: Jun. 21, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-12552
In SweetScape 010 Editor 9.0.1, an integer overflow during the initialization of variables could allow an attacker to cause a denial of service.... Read more
Affected Products : 010_editor- Published: Jul. 22, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2007-3732
In Linux 2.6 before 2.6.23, the TRACE_IRQS_ON function in iret_exc calls a C function without ensuring that the segments are set properly. The kernel's %fs needs to be restored before the call in TRACE_IRQS_ON and before enabling interrupts, so that "curr... Read more
Affected Products : linux_kernel- Published: Nov. 07, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUM- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-18446
An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4. It has Insecure Permissions (issue 1 of 2).... Read more
Affected Products : gitlab- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-8731
A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved permission validation. This issue is fixed in iOS 13. Processing a maliciously crafted file may disclose user information.... Read more
Affected Products : iphone_os- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-6212
Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenti... Read more
- Published: Apr. 24, 2020
- Modified: Nov. 21, 2024