Latest CVE Feed
-
5.5
MEDIUMCVE-2012-0248
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.... Read more
- EPSS Score: %0.29
- Published: Jun. 05, 2012
- Modified: Apr. 11, 2025
-
5.5
MEDIUMCVE-2015-4319
The password-change feature in the administrative web interface in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 improperly performs authorization, which allows remote authenticated users to reset arbitrary active-user passwords vi... Read more
Affected Products : telepresence_video_communication_server_software- EPSS Score: %0.60
- Published: Aug. 20, 2015
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2015-4315
The Call Policy Configuration page in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.3 improperly validates external DTDs, which allows remote authenticated users to read arbitrary files or cause a denial of service via a crafted XML ... Read more
Affected Products : telepresence_video_communication_server_software- EPSS Score: %0.46
- Published: Aug. 20, 2015
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-3712
Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.... Read more
- EPSS Score: %0.12
- Published: May. 11, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2015-4299
Cisco Unified Web and E-Mail Interaction Manager 9.0(2) improperly performs authorization, which allows remote authenticated users to remove default messaging-queue system folders via unspecified vectors, aka Bug ID CSCuo89046.... Read more
Affected Products : unified_web_and_e-mail_interaction_manager- EPSS Score: %0.55
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2020-6178
SAP Enable Now, before version 1911, sends the Session ID cookie value in URL. This might be stolen from the browser history or log files, leading to Information Disclosure.... Read more
Affected Products : enable_now- EPSS Score: %0.09
- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-3464
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which allows remote authenticated users to... Read more
Affected Products : jboss_enterprise_application_platform- EPSS Score: %0.19
- Published: Aug. 19, 2014
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2020-6106
An exploitable information disclosure vulnerability exists in the init_node_manager functionality of F2fs-Tools F2fs.Fsck 1.12 and 1.13. A specially crafted filesystem can be used to disclose information. An attacker can provide a malicious file to trigge... Read more
Affected Products : f2fs-tools- EPSS Score: %0.29
- Published: Oct. 15, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2015-4182
The administrative web interface in Cisco Identity Services Engine (ISE) before 1.3 allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or change settings, via unspecified vectors, aka Bug ID CSCui720... Read more
Affected Products : identity_services_engine_software- EPSS Score: %0.21
- Published: Jun. 12, 2015
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-8694
The bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted BMP image, a different vulnerability than CVE-2016-8695 and CVE-2016-8696.... Read more
- EPSS Score: %0.28
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2020-5989
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which it can dereference a NULL pointer, which may lead to denial of service. This affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4) and version 11.0.... Read more
Affected Products : virtual_gpu_manager- EPSS Score: %0.05
- Published: Oct. 02, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-35903
In the Linux kernel, the following vulnerability has been resolved: x86/bpf: Fix IP after emitting call depth accounting Adjust the IP passed to `emit_patch` so it calculates the correct offset for the CALL instruction if `x86_call_depth_emit_accounting... Read more
Affected Products : linux_kernel- Published: May. 19, 2024
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-5965
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the DirectX 11 user mode driver (nvwgf2um/x.dll), in which a specially crafted shader can cause an out of bounds access, leading to denial of service.... Read more
Affected Products : gpu_display_driver quadro_firmware geforce_firmware tesla_firmware nvs_firmware quadro tesla geforce nvs- EPSS Score: %0.05
- Published: Jun. 25, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-5898
In versions 7.1.5-7.1.9, BIG-IP Edge Client Windows Stonewall driver does not sanitize the pointer received from the userland. A local user on the Windows client system can send crafted DeviceIoControl requests to \\.\urvpndrv device causing the Windows k... Read more
- EPSS Score: %0.07
- Published: May. 12, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-9836
ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service via a crafted xpm file.... Read more
Affected Products : imagemagick- EPSS Score: %0.39
- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2014-9810
The dpx file handler in ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a malformed dpx file.... Read more
Affected Products : imagemagick- EPSS Score: %0.46
- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2020-5908
In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in the local log files.... Read more
Affected Products : big-ip_access_policy_manager- EPSS Score: %0.09
- Published: Jul. 01, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-11359
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.... Read more
- EPSS Score: %3.30
- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11626
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDFTokenizer::resolveLiteral function in QPDFTokenizer.cc after four consecutive calls to QPDFObj... Read more
Affected Products : qpdf- EPSS Score: %0.34
- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2020-5825
Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an arbitrary file write vulnerability, which is a type of issue whe... Read more
- EPSS Score: %0.09
- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024