Latest CVE Feed
-
5.5
MEDIUMCVE-2022-38407
Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Explo... Read more
- Published: Sep. 16, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-38406
Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Explo... Read more
- Published: Sep. 16, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-54476
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to access user-sensitive data.... Read more
Affected Products : macos- Published: Dec. 12, 2024
- Modified: Dec. 19, 2024
-
5.5
MEDIUMCVE-2022-38235
XPDF commit ffaf11c was discovered to contain a segmentation violation via DCTStream::getChar() at /xpdf/Stream.cc.... Read more
Affected Products : xpdf- Published: Aug. 16, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-8357
An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c allows a NULL pointer dereference.... Read more
Affected Products : sound_exchange- Published: Feb. 15, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-54474
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to access user-sensitive data.... Read more
Affected Products : macos- Published: Dec. 12, 2024
- Modified: Dec. 16, 2024
-
5.5
MEDIUMCVE-2022-38043
Windows Security Support Provider Interface Information Disclosure Vulnerability... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 +11 more products- Published: Oct. 11, 2022
- Modified: Jan. 02, 2025
-
5.5
MEDIUMCVE-2022-37985
Windows Graphics Component Information Disclosure Vulnerability... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 +12 more products- Published: Oct. 11, 2022
- Modified: Jan. 02, 2025
-
5.5
MEDIUMCVE-2022-37939
A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnerability could be locally exploited to allow disclosure of information. HPE has made the following software to resolve the vulnerability ... Read more
- Published: Mar. 10, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-38025
Windows Distributed File System (DFS) Information Disclosure Vulnerability... Read more
- Published: Oct. 11, 2022
- Modified: Jan. 02, 2025
-
5.5
MEDIUMCVE-2024-54469
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7, macOS Sequoia 15, macOS Sonoma 14.7, visionOS 2, iOS 18 and iPadOS 18. A local user may be able to leak sensitive user information.... Read more
- Published: Mar. 10, 2025
- Modified: Mar. 14, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2022-37911
Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume sy... Read more
- Published: Dec. 12, 2022
- Modified: May. 02, 2025
-
5.5
MEDIUMCVE-2022-37926
A vulnerability within the web-based management interface of EdgeConnect Enterprise could allow a remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface by uploading a specially crafted file. A successful exp... Read more
Affected Products : edgeconnect_enterprise- Published: Dec. 12, 2022
- Modified: Apr. 24, 2025
-
5.5
MEDIUMCVE-2024-54460
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: iso: Fix circular lock in iso_listen_bis This fixes the circular locking dependency warning below, by releasing the socket lock before enterning iso_listen_bis, to avoid any ... Read more
Affected Products : linux_kernel- Published: Jan. 11, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Race Condition
-
5.5
MEDIUMCVE-2022-37292
Tenda AX12 V22.03.01.21_CN is vulnerable to Buffer Overflow. This overflow is triggered in the sub_42FDE4 function, which satisfies the request of the upper-level interface function sub_430124, that is, handles the post request under /goform/SetIpMacBind.... Read more
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-37380
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a ma... Read more
- Published: Mar. 29, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-37382
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a ma... Read more
- Published: Mar. 29, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-37302
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a crash of the Control Expert software when an incorrect project file is opened. Affected Products: EcoStruxure Control Expert(V15.1 H... Read more
Affected Products : ecostruxure_control_expert- Published: Sep. 13, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-37351
This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- Published: Mar. 29, 2023
- Modified: Feb. 18, 2025
-
5.5
MEDIUMCVE-2022-37290
GNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename application crash via a pasted ZIP archive.... Read more
- Published: Nov. 14, 2022
- Modified: May. 01, 2025