Latest CVE Feed
-
5.5
MEDIUMCVE-2019-8519
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Mojave 10.14.4. An application may be able to read restricted memory.... Read more
- EPSS Score: %0.13
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2015-8733
The ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationships between record lengths and record header lengths, which allows remote atta... Read more
Affected Products : wireshark- EPSS Score: %1.63
- Published: Jan. 04, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2019-8817
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.1. An application may be able to read restricted memory.... Read more
- EPSS Score: %0.31
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2015-8777
The process_envvars function in elf/rtld.c in the GNU C Library (aka glibc or libc6) before 2.23 allows local users to bypass a pointer-guarding protection mechanism via a zero value of the LD_POINTER_GUARD environment variable.... Read more
Affected Products : glibc- EPSS Score: %0.06
- Published: Jan. 20, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2020-35493
A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binut... Read more
- EPSS Score: %0.36
- Published: Jan. 04, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2015-8950
arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products, does not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory by triggerin... Read more
Affected Products : linux_kernel- EPSS Score: %0.15
- Published: Oct. 10, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-4755
Terminal in Apple OS X before 10.12 uses weak permissions for the .bash_history and .bash_session files, which allows local users to obtain sensitive information via unspecified vectors.... Read more
- EPSS Score: %0.04
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2019-3633
Buffer overflow in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.2.8 allows local user to cause the Windows operating system to "blue screen" via a carefully constructed message sent to DLPe which bypasses DLPe internal checks and resu... Read more
- EPSS Score: %0.05
- Published: Aug. 21, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-0470
In extend_frame_highbd of restoration.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Pr... Read more
Affected Products : android- EPSS Score: %0.69
- Published: Dec. 14, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-36776
In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/cpufreq_cooling: Fix slab OOB issue Slab OOB issue is scanned by KASAN in cpu_power_to_freq(). If power is limited below the power of OPP0 in EM table, it will cause sla... Read more
Affected Products : linux_kernel- Published: Feb. 27, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2015-9252
An issue was discovered in QPDF before 7.0.0. Endless recursion causes stack exhaustion in QPDFTokenizer::resolveLiteral() in QPDFTokenizer.cc, related to the QPDF::resolve function in QPDF.cc.... Read more
Affected Products : qpdf- EPSS Score: %0.31
- Published: Feb. 13, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-10762
An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes recording passwords to the cmd_history.log file which is world-readable. This flaw allows local users to o... Read more
Affected Products : gluster-block- EPSS Score: %0.08
- Published: Nov. 24, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-10781
A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the ability to read the /sys/class/zram-control/hot_add file can create ZRAM device nodes in the /dev/ directory. This read allocates kern... Read more
- EPSS Score: %0.10
- Published: Sep. 16, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-5721
In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by changing the memory-management approach so that a use-after-free is avoided.... Read more
Affected Products : wireshark- EPSS Score: %0.19
- Published: Jan. 08, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-12135
bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() parameter bytesNeeded could have an integer overflow via properly constructed bson input.... Read more
- EPSS Score: %0.35
- Published: Apr. 24, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-7222
The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.... Read more
Affected Products : linux_kernel ubuntu_linux enterprise_linux fedora debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation leap enterprise_linux_server_aus +8 more products- EPSS Score: %0.04
- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-0181
Microsoft Windows 10 Gold and 1511 allows local users to bypass the Virtual Secure Mode Hypervisor Code Integrity (HVCI) protection mechanism and perform RWX markings of kernel-mode pages via a crafted application, aka "Hypervisor Code Integrity Security ... Read more
Affected Products : windows_10- EPSS Score: %0.37
- Published: May. 11, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2013-5653
The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted postscript file.... Read more
- EPSS Score: %0.24
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2020-13844
Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka "straight-line speculation.... Read more
Affected Products : leap cortex-a53_firmware cortex-a57_firmware cortex-a72_firmware cortex-a73_firmware cortex-a72 cortex-a32_firmware cortex-a35_firmware cortex-a34_firmware cortex-a53 +5 more products- EPSS Score: %0.18
- Published: Jun. 08, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-14402
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings.... Read more
- EPSS Score: %1.13
- Published: Jun. 17, 2020
- Modified: Nov. 21, 2024