Latest CVE Feed
-
5.5
MEDIUMCVE-2018-20357
A NULL pointer dereference was discovered in sbr_process_channel of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash.... Read more
- EPSS Score: %0.34
- Published: Dec. 22, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-20511
An issue was discovered in the Linux kernel before 4.18.11. The ipddp_ioctl function in drivers/net/appletalk/ipddp.c allows local users to obtain sensitive kernel address information by leveraging CAP_NET_ADMIN to read the ipddp_route dev and next fields... Read more
- EPSS Score: %0.08
- Published: Dec. 27, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2015-5301
providers/saml2/admin.py in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.2 and 1.1.x before 1.1.1 does not properly check permissions, which allows remote authenticated users to cause a denial of service by deleting a SAML2 Service Provi... Read more
Affected Products : ipsilon- EPSS Score: %0.72
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2012-3367
Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the web interface, which allows remote attackers with permissions to revoke end entity certificates to revoke... Read more
- EPSS Score: %0.40
- Published: Aug. 13, 2012
- Modified: Apr. 11, 2025
-
5.5
MEDIUMCVE-2018-3639
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a s... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_server_2008 windows_server_2012 windows_server_2016 ubuntu_linux enterprise_linux debian_linux enterprise_linux_desktop +311 more products- EPSS Score: %46.74
- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-6834
Heap-based buffer overflow in the ulaw2linear_buf function in G711.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0, 0.2.7 allows remote attackers to cause a denial of service (crash) via a crafted file.... Read more
- EPSS Score: %2.65
- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2022-48809
In the Linux kernel, the following vulnerability has been resolved: net: fix a memleak when uncloning an skb dst and its metadata When uncloning an skb dst and its associated metadata, a new dst+metadata is allocated and later replaces the old one in th... Read more
Affected Products : linux_kernel- Published: Jul. 16, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-9474
In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.... Read more
Affected Products : ytnef- EPSS Score: %0.20
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2018-6253
NVIDIA GPU Display Driver contains a vulnerability in the DirectX and OpenGL Usermode drivers where a specially crafted pixel shader can cause infinite recursion leading to denial of service.... Read more
- EPSS Score: %0.05
- Published: Apr. 02, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-9954
The getvalue function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted tekhex... Read more
Affected Products : binutils- EPSS Score: %0.42
- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2018-7454
A NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.... Read more
Affected Products : xpdf- EPSS Score: %0.15
- Published: Feb. 24, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-7740
The resv_map_release function in mm/hugetlb.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (BUG) via a crafted application that makes mmap system calls and has a large pgoff argument to the remap_file_pages system cal... Read more
- EPSS Score: %0.08
- Published: Mar. 07, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-1000036
In Artifex MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser allow an attacker to cause a denial of service (memory leak) via a crafted file.... Read more
- EPSS Score: %0.31
- Published: May. 24, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-8105
The JPXStream::fillReadBuf function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.... Read more
Affected Products : xpdf- EPSS Score: %0.14
- Published: Mar. 14, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-1000199
The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptrace. T... Read more
- EPSS Score: %0.33
- Published: May. 24, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-10372
process_cu_tu_index in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted binary file, as demonstrated by readelf.... Read more
Affected Products : enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation binutils- EPSS Score: %0.42
- Published: Apr. 25, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-2085
The evm_verify_hmac function in security/integrity/evm/evm_main.c in the Linux kernel before 4.5 does not properly copy data, which makes it easier for local users to forge MAC values via a timing side-channel attack.... Read more
Affected Products : linux_kernel- EPSS Score: %0.07
- Published: Apr. 27, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2017-6188
Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user.... Read more
- EPSS Score: %0.14
- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6500
An issue was discovered in ImageMagick 6.9.7. A specially crafted sun file triggers a heap-based buffer over-read.... Read more
- EPSS Score: %0.27
- Published: Mar. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6838
Integer overflow in sfcommands/sfconvert.c in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.... Read more
Affected Products : audiofile- EPSS Score: %2.32
- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025