Latest CVE Feed
-
5.5
MEDIUMCVE-2017-1441
IBM Emptoris Services Procurement 10.0.0.5 could allow a local user to view sensitive information stored locally due to improper access control. IBM X-Force ID: 128106.... Read more
Affected Products : emptoris_services_procurement- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2014-3968
The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x allows local guest HVM administrators to cause a denial of service (host crash) via a large number of crafted requests, which trigger an error messages to be logged.... Read more
- Published: Jun. 05, 2014
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2021-23886
Denial of Service vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to cause a BSoD through suspending a process, modifying the processes memory and restarting it. This is tr... Read more
- Published: Apr. 15, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-23827
Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories. It fails to effectively clear cached picture... Read more
- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-23566
The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.... Read more
Affected Products : nanoid- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-18925
opentmpfiles through 0.3.1 allows local users to take ownership of arbitrary files because d entries are mishandled and allow a symlink attack.... Read more
Affected Products : opentmpfiles- Published: Oct. 26, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-23210
A floating point exception (divide-by-zero) issue was discovered in SoX in functon read_samples() of voc.c file. An attacker with a crafted file, could cause an application to crash.... Read more
- Published: Aug. 25, 2022
- Modified: Jun. 27, 2025
-
5.5
MEDIUMCVE-2021-23159
A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function lsx_read_w_buf() in formats_i.c file. The vulnerability is exploitable with a crafted file, that could cause an application to crash.... Read more
- Published: Aug. 25, 2022
- Modified: Jun. 27, 2025
-
5.5
MEDIUMCVE-2012-1096
NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.... Read more
- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-29626
In FreeBSD 13.0-STABLE before n245117, 12.2-STABLE before r369551, 11.4-STABLE before r369559, 13.0-RC5 before p1, 12.2-RELEASE before p6, and 11.4-RELEASE before p9, copy-on-write logic failed to invalidate shared memory page mappings between multiple pr... Read more
Affected Products : freebsd- Published: Apr. 07, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-23020
The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could lead to predictable keys.... Read more
Affected Products : nginx_controller- Published: Jun. 01, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2011-4594
The __sys_sendmsg function in net/socket.c in the Linux kernel before 3.1 allows local users to cause a denial of service (system crash) via crafted use of the sendmmsg system call, leading to an incorrect pointer dereference.... Read more
Affected Products : linux_kernel- Published: May. 17, 2012
- Modified: Apr. 11, 2025
-
5.5
MEDIUMCVE-2011-2479
The Linux kernel before 2.6.39 does not properly create transparent huge pages in response to a MAP_PRIVATE mmap system call on /dev/zero, which allows local users to cause a denial of service (system crash) via a crafted application.... Read more
Affected Products : linux_kernel- Published: Mar. 01, 2013
- Modified: Apr. 11, 2025
-
5.5
MEDIUMCVE-2021-22853
The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access sensitive data via a specific data packet, such as user’s login information, further causing the login function not to work.... Read more
Affected Products : hr_portal- Published: Feb. 17, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-22809
A CWE-125:Out-of-Bounds Read vulnerability exists that could cause unintended data disclosure when a malicious *.gd1 configuration file is loaded into the GUIcon tool. Affected Product: Eurotherm by Schneider Electric GUIcon Version 2.0 (Build 683.003) an... Read more
Affected Products : guicon- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-22781
Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), an... Read more
- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-18549
An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory because aac_send_raw_srb does not initialize the reply structure.... Read more
Affected Products : linux_kernel- Published: Aug. 19, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2009-0992
Unspecified vulnerability in the Advanced Queuing component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality and integrity, related to DBMS_AQIN. NOTE: the previous information was obtained fr... Read more
- Published: Apr. 15, 2009
- Modified: Apr. 09, 2025
-
5.5
MEDIUMCVE-2017-18449
cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_roundcube_mysql2sqlite (SEC-254).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-22571
A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process before the files are loaded in BigQuery. We recommend upgrading to version 1.0.3 or above.... Read more
Affected Products : sa360_webquery_to_bigquery_exporter- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024