Latest CVE Feed
-
5.5
MEDIUMCVE-2017-7542
The ip6_find_1stfragopt function in net/ipv6/output_core.c in the Linux kernel through 4.12.3 allows local users to cause a denial of service (integer overflow and infinite loop) by leveraging the ability to open a raw socket.... Read more
Affected Products : linux_kernel- EPSS Score: %0.03
- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7594
The OJPEGReadHeaderInfoSecTablesDcTable function in tif_ojpeg.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (memory leak) via a crafted image.... Read more
Affected Products : libtiff- EPSS Score: %0.44
- Published: Apr. 09, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2019-1046
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_server windows_10_1607 +8 more products- EPSS Score: %7.62
- Published: Jun. 12, 2019
- Modified: May. 20, 2025
-
5.5
MEDIUMCVE-2018-13094
An issue was discovered in fs/xfs/libxfs/xfs_attr_leaf.c in the Linux kernel through 4.17.3. An OOPS may occur for a corrupted xfs image after xfs_da_shrink_inode() is called with a NULL bp.... Read more
- EPSS Score: %0.25
- Published: Jul. 03, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-8949
A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.... Read more
Affected Products : sitescope- EPSS Score: %0.26
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-1452
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140047.... Read more
- EPSS Score: %0.07
- Published: May. 25, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-9605
The vmw_gb_surface_define_ioctl function (accessible via DRM_IOCTL_VMW_GB_SURFACE_CREATE) in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.11.4 defines a backup_handle variable but does not give it an initial value. If one attempts... Read more
Affected Products : linux_kernel- EPSS Score: %0.11
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2019-12379
An issue was discovered in con_insert_unipair in drivers/tty/vt/consolemap.c in the Linux kernel through 5.1.5. There is a memory leak in a certain case of an ENOMEM outcome of kmalloc. NOTE: This id is disputed as not being an issue... Read more
Affected Products : linux_kernel- EPSS Score: %0.08
- Published: May. 28, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-12415
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML Extern... Read more
- EPSS Score: %0.02
- Published: Oct. 23, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-9868
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.... Read more
- EPSS Score: %0.12
- Published: Jun. 25, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2018-0202
clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms wh... Read more
- EPSS Score: %2.01
- Published: Mar. 27, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-13134
ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c.... Read more
- EPSS Score: %0.10
- Published: Jul. 01, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-17788
In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.... Read more
- EPSS Score: %0.50
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2018-15942
Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.... Read more
- EPSS Score: %2.25
- Published: Oct. 12, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-0719
Cross-site Scripting (XSS) vulnerability in NAS devices of QNAP Systems Inc. QTS allows attackers to inject javascript. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and prior versions on build 20180711; version 4.3.3 and prior versions on build... Read more
Affected Products : qts- EPSS Score: %0.23
- Published: Nov. 27, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-19478
In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long running computation when parsing the file.... Read more
- EPSS Score: %0.68
- Published: Jan. 02, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-19755
There is an illegal address access at asm/preproc.c (function: is_mmacro) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service (out-of-bounds array access) because a certain conversion can result in a negative integer.... Read more
- EPSS Score: %0.14
- Published: Nov. 30, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-18233
An issue was discovered in Exempi before 2.4.4. Integer overflow in the Chunk class in XMPFiles/source/FormatSupport/RIFF.cpp allows remote attackers to cause a denial of service (infinite loop) via crafted XMP data in a .avi file.... Read more
- EPSS Score: %0.30
- Published: Mar. 15, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-3279
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services on SharePoint S... Read more
Affected Products : office word sharepoint_server office_web_apps excel powerpoint excel_rt word_rt powerpoint_rt- EPSS Score: %25.76
- Published: Jul. 13, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2019-1734
A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to view sensitive system files that should be restricted. The attacker could use this informatio... Read more
Affected Products : nx-os firepower_extensible_operating_system nexus_7000 nexus_5548p nexus_5548up nexus_5596up nexus_3048 nexus_3548 mds_9100 nexus_5596t +84 more products- EPSS Score: %0.20
- Published: Nov. 05, 2019
- Modified: Nov. 21, 2024