Latest CVE Feed
-
5.5
MEDIUMCVE-2016-7409
The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG_TRACE, allows local users to read process memory via the -v argument, related to a failed remote ident.... Read more
Affected Products : dropbear_ssh- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-7392
Heap-based buffer overflow in the pstoedit_suffix_table_init function in output-pstoedit.c in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted bmp image file.... Read more
Affected Products : autotrace- Published: Feb. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-2388
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireFamily" component. It allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-2390
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves symlink mishandling in the "libarchive" component. It allows... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-2385
An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the "Safari Login AutoFill" component. It allows local users to obtain access to locked keychain items via unspecified vectors.... Read more
Affected Products : safari- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-5608
Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect availability via vectors related to Core, a different vulnerability than CVE-2016-5613.... Read more
Affected Products : vm_virtualbox- Published: Oct. 25, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2017-2328
An information leak vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, user to elevate their permissions through reading unprivileged information stored in the... Read more
Affected Products : northstar_controller- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-2327
A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to consume large amounts of system resources leading to a cascading denial of services.... Read more
Affected Products : northstar_controller- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-4649
Audio in Apple OS X before 10.11.6 allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.... Read more
- Published: Jul. 22, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-4490
Integer overflow in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to inconsistent use of the long and int types for lengths.... Read more
Affected Products : libiberty- Published: Feb. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-3954
web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status. NOTE: this issue can be leveraged by remote attackers to execute arbitrary code using CVE-2016-3957.... Read more
Affected Products : web2py- Published: Feb. 06, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-3315
Microsoft OneNote 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to obtain sensitive information via a crafted OneNote file, aka "Microsoft OneNote Information Disclosure Vulnerability."... Read more
- Published: Aug. 09, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-2318
GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartElement function in coders/svg.c, and (3) TraceArcPath func... Read more
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-2178
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.... Read more
- Published: Jun. 20, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-1981
QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing data via transmit or receive descriptors, provided the initial receive/transmit descriptor head (TDH/RDH) is set ... Read more
- Published: Dec. 29, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-1922
QEMU (aka Quick Emulator) built with the TPR optimization for 32-bit Windows guests support is vulnerable to a null pointer dereference flaw. It occurs while doing I/O port write operations via hmp interface. In that, 'current_cpu' remains null, which lea... Read more
- Published: Dec. 29, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-1838
The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read)... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-1836
Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service via a cra... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2024-44273
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.1 and iPadOS 18.1, visionOS 2.1, macOS Sonoma 14.7.1, watchOS 11.1, tvOS 18.1. A malicious app may be able to access private information.... Read more
- Published: Oct. 28, 2024
- Modified: Dec. 09, 2024
-
5.5
MEDIUMCVE-2016-1372
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file.... Read more
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025