Latest CVE Feed
-
5.5
MEDIUMCVE-2007-4497
Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Serv... Read more
- EPSS Score: %0.32
- Published: Sep. 21, 2007
- Modified: Apr. 09, 2025
-
5.5
MEDIUMCVE-2017-3157
By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to s... Read more
- EPSS Score: %1.06
- Published: Nov. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2018-19625
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the dissection engine could crash. This was addressed in epan/tvbuff_composite.c by preventing a heap-based buffer over-read.... Read more
- EPSS Score: %0.29
- Published: Nov. 29, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-15025
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted ELF file.... Read more
Affected Products : binutils- EPSS Score: %0.33
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2018-20005
An issue has been found in Mini-XML (aka mxml) 2.12. It is a use-after-free in mxmlWalkNext in mxml-search.c, as demonstrated by mxmldoc.... Read more
- EPSS Score: %0.19
- Published: Dec. 10, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-15642
In lsx_aiffstartread in aiff.c in Sound eXchange (SoX) 14.4.2, there is a Use-After-Free vulnerability triggered by supplying a malformed AIFF file.... Read more
- EPSS Score: %0.60
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2015-4319
The password-change feature in the administrative web interface in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 improperly performs authorization, which allows remote authenticated users to reset arbitrary active-user passwords vi... Read more
Affected Products : telepresence_video_communication_server_software- EPSS Score: %0.60
- Published: Aug. 20, 2015
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2017-5844
The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted ASF file.... Read more
Affected Products : gstreamer- EPSS Score: %0.76
- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6596
partclone.chkimg in partclone 0.2.89 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the partclone image header. An attacker may be able to launch a 'Denial of Service attack' in the context of the user running the... Read more
Affected Products : partclone- EPSS Score: %0.18
- Published: Mar. 10, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-17813
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in the pp_list_one_macro function in asm/preproc.c that will cause a remote denial of service attack, related to mishandling of line-syntax errors.... Read more
- EPSS Score: %0.18
- Published: Dec. 21, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7036
An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.... Read more
- EPSS Score: %0.25
- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-18216
In fs/ocfs2/cluster/nodemanager.c in the Linux kernel before 4.15, local users can cause a denial of service (NULL pointer dereference and BUG) because a required mutex is not used.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Mar. 05, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-4224
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is ... Read more
- EPSS Score: %0.04
- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-2390
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves symlink mishandling in the "libarchive" component. It allows... Read more
- EPSS Score: %0.09
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2018-5711
gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated by a... Read more
- EPSS Score: %6.06
- Published: Jan. 16, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-5730
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which ... Read more
- EPSS Score: %1.11
- Published: Mar. 06, 2018
- Modified: May. 05, 2025
-
5.5
MEDIUMCVE-2017-2599
Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing items they don't have access to (SECURITY-321).... Read more
Affected Products : jenkins- EPSS Score: %0.06
- Published: Apr. 11, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-6191
The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent validation.... Read more
Affected Products : mujs- EPSS Score: %3.21
- Published: Jan. 24, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-8101
The JPXStream::inverseTransformLevel function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.... Read more
Affected Products : xpdf- EPSS Score: %0.15
- Published: Mar. 14, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-8445
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8336, ... Read more
- EPSS Score: %4.08
- Published: Sep. 13, 2018
- Modified: Nov. 21, 2024