Latest CVE Feed
-
5.5
MEDIUMCVE-2018-9867
In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the SonicWall Administrators user group attempt to download imported certificates. This vulnerability affected Soni... Read more
- Published: Feb. 19, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-11833
fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem.... Read more
- Published: May. 15, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-15731
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validating the output buffer address value from IOCtl 0x8000205B.... Read more
Affected Products : antimalware- Published: Jun. 21, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-12552
In SweetScape 010 Editor 9.0.1, an integer overflow during the initialization of variables could allow an attacker to cause a denial of service.... Read more
Affected Products : 010_editor- Published: Jul. 22, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2007-3732
In Linux 2.6 before 2.6.23, the TRACE_IRQS_ON function in iret_exc calls a C function without ensuring that the segments are set properly. The kernel's %fs needs to be restored before the call in TRACE_IRQS_ON and before enabling interrupts, so that "curr... Read more
Affected Products : linux_kernel- Published: Nov. 07, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUM- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-18446
An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4. It has Insecure Permissions (issue 1 of 2).... Read more
Affected Products : gitlab- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-8731
A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved permission validation. This issue is fixed in iOS 13. Processing a maliciously crafted file may disclose user information.... Read more
Affected Products : iphone_os- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-6212
Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenti... Read more
- Published: Apr. 24, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-0091
In mnld, an incorrect configuration in driver_cfg of mnld for meta factory mode.Product: AndroidVersions: Android SoCAndroid ID: A-149808700... Read more
Affected Products : android- Published: May. 14, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-15470
ffjpeg through 2020-02-24 has a heap-based buffer overflow in jfif_decode in jfif.c.... Read more
- Published: Jul. 01, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-14392
An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.... Read more
- Published: Sep. 16, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-0386
In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverability with User execution privileges ne... Read more
Affected Products : android- Published: Sep. 17, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-26567
An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any access reboots the device, rendering it therefore unusable for several minutes.... Read more
- Published: Oct. 08, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-9979
A trust issue was addressed by removing a legacy API. This issue is fixed in iOS 14.0 and iPadOS 14.0, tvOS 14.0. An attacker may be able to misuse a trust relationship to download malicious content.... Read more
- Published: Oct. 27, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-35927
An issue was discovered in the thex crate through 2020-12-08 for Rust. Thex<T> allows cross-thread data races of non-Send types.... Read more
Affected Products : thex- Published: Dec. 31, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-24226
The issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may be able to access private information.... Read more
Affected Products : xcode- Published: Mar. 31, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2023-28899
By sending a specific reset UDS request via OBDII port of Skoda vehicles, it is possible to cause vehicle engine shutdown and denial of service of other vehicle components even when the vehicle is moving at a high speed. No safety critical functions affec... Read more
- Published: Jan. 12, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-48340
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed... Read more
- Published: Jan. 18, 2024
- Modified: Jun. 20, 2025
-
5.5
MEDIUMCVE-2023-52532
In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix TX CQE error handling For an unknown TX CQE error type (probably from a newer hardware), still free the SKB, update the queue tail, etc., otherwise the accounting will be... Read more
Affected Products : linux_kernel- Published: Mar. 02, 2024
- Modified: Jan. 16, 2025