Latest CVE Feed
-
5.5
MEDIUMCVE-2017-7452
The iwbmp_read_info_header function in imagew-bmp.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.... Read more
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7381
The doc/PdfPage.cpp:609:23 code in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.... Read more
Affected Products : podofo- Published: Apr. 03, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2022-4128
A NULL pointer dereference issue was discovered in the Linux kernel in the MPTCP protocol when traversing the subflow list at disconnect time. A local user could use this flaw to potentially crash the system causing a denial of service.... Read more
- Published: Nov. 28, 2022
- Modified: Jun. 25, 2025
-
5.5
MEDIUMCVE-2017-7274
The r_pkcs7_parse_cms function in libr/util/r_pkcs7.c in radare2 1.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PE file.... Read more
Affected Products : radare2- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7299
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an invalid read (of size 8) because the code to emit relocs (bfd_elf_final_link function in bfd/elflink.c) does not check the format of the input file before t... Read more
Affected Products : binutils- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2021-30331
Possible buffer overflow due to improper data validation of external commands sent via DIAG interface in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearab... Read more
Affected Products : qca6390_firmware qca6391_firmware qca6426_firmware qca6436_firmware sd_8_gen1_5g_firmware sd865_5g_firmware sd870_firmware sd888_5g_firmware sdx55m_firmware sdxr2_5g_firmware +144 more products- Published: Apr. 01, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-7224
The find_nearest_line function in objdump in GNU Binutils 2.28 is vulnerable to an invalid write (of size 1) while disassembling a corrupt binary that contains an empty function name, leading to a program crash.... Read more
Affected Products : binutils- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7262
The AMD Ryzen processor with AGESA microcode through 2017-01-27 allows local users to cause a denial of service (system hang) via an application that makes a long series of FMA3 instructions, as demonstrated by the Flops test suite.... Read more
Affected Products : ryzen- Published: Mar. 25, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7150
An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "Security" component. It allows attackers to bypass the keychain access prompt, and consequently extract passwords, via a synthet... Read more
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7119
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "IOFireWireFamily" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.... Read more
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2022-34728
Windows Graphics Component Information Disclosure Vulnerability... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 +11 more products- Published: Sep. 13, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-34682
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a null-pointer dereference, which may lead to denial of service.... Read more
Affected Products : linux_kernel virtual_gpu cloud_gaming hypervisor enterprise_linux_kernel-based_virtual_machine vsphere- Published: Dec. 30, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-35671
Adobe Acrobat Reader versions 22.001.20169 (and earlier), 20.005.30362 (and earlier) and 17.012.30249 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vuln... Read more
- Published: Aug. 11, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-7075
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Notes" component. It allows local users to obtain sensitive information by reading search results that contain locked-note content.... Read more
Affected Products : iphone_os- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-7072
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "iBooks" component. It allows remote attackers to cause a denial of service (persistent outage) via a crafted iBooks file.... Read more
Affected Products : iphone_os- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7045
An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.... Read more
- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2024-49888
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a sdiv overflow issue Zac Ecob reported a problem where a bpf program may cause kernel crash due to the following error: Oops: divide error: 0000 [#1] PREEMPT SMP KASAN PTI ... Read more
Affected Products : linux_kernel- Published: Oct. 21, 2024
- Modified: Nov. 13, 2024
-
5.5
MEDIUMCVE-2024-49541
Illustrator versions 29.0.0, 28.7.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this i... Read more
- Published: Dec. 10, 2024
- Modified: Aug. 15, 2025
-
5.5
MEDIUMCVE-2017-7079
An issue was discovered in certain Apple products. iTunes before 12.7 is affected. The issue involves the "Data Sync" component. It allows attackers to access iOS backups (written by iTunes) via a crafted app.... Read more
Affected Products : itunes- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7113
An issue was discovered in certain Apple products. iOS before 11.1 is affected. The issue involves the "UIKit" component. It allows attackers to bypass intended read restrictions for secure text fields via vectors involving a focus-change event.... Read more
Affected Products : iphone_os- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025