Latest CVE Feed
-
5.5
MEDIUMCVE-2016-7906
magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a crafted file.... Read more
- Published: Jan. 18, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-7056
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.... Read more
- Published: Sep. 10, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0375
In onPackageModified of VoiceInteractionManagerService.java, there is a possible change of default applications due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interac... Read more
Affected Products : android- Published: Mar. 10, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0377
In DeltaPerformer::Write of delta_performer.cc, there is a possible use of untrusted input due to improper input validation. This could lead to a local bypass of defense in depth protections with no additional execution privileges needed. User interaction... Read more
Affected Products : android- Published: Mar. 10, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-6327
drivers/infiniband/ulp/srpt/ib_srpt.c in the Linux kernel before 4.5.1 allows local users to cause a denial of service (NULL pointer dereference and system crash) by using an ABORT_TASK command to abort a device write operation.... Read more
Affected Products : linux_kernel- Published: Oct. 16, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2021-0382
In checkSlicePermission of SliceManagerService.java, there is a possible resource exposure due to an incorrect permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed... Read more
Affected Products : android- Published: Mar. 10, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2015-7898
Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).... Read more
- Published: Jun. 27, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2015-7889
The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions for the com.samsung.android.email.intent.action.QUICK_REPLY_BACKGROUND service action, which might allow remote attackers with knowledge... Read more
- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-4493
The demangle_template_value_parm and do_hpacc_template_literal functions in cplus-dem.c in libiberty allow remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted binary.... Read more
Affected Products : libiberty- Published: Feb. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-4489
Integer overflow in the gnu_special function in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to the "demangling of virtual tables."... Read more
Affected Products : libiberty- Published: Feb. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-4352
Integer overflow in the demuxer function in libmpdemux/demux_gif.c in Mplayer allows remote attackers to cause a denial of service (crash) via large dimensions in a gif file.... Read more
Affected Products : libavformat- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2021-0338
In SystemSettingsValidators, there is a possible permanent denial of service due to missing bounds checks on UI settings. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Pro... Read more
Affected Products : android- Published: Feb. 10, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2015-7890
Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung S6 Edge, allow local users to cause a denial of service (memory corruption) via a large (1) buffer or (2) size parameter.... Read more
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2015-7802
gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitialized memory read) via a crafted GIF file.... Read more
- Published: Apr. 20, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2021-0321
In enforceDumpPermissionForPackage of ActivityManagerService.java, there is a possible way to determine if a package is installed due to side channel information disclosure. This could lead to local information disclosure with no additional execution priv... Read more
Affected Products : android- Published: Jan. 11, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-35904
In the Linux kernel, the following vulnerability has been resolved: selinux: avoid dereference of garbage after mount failure In case kern_mount() fails and returns an error pointer return in the error branch instead of continuing and dereferencing the ... Read more
Affected Products : linux_kernel- Published: May. 19, 2024
- Modified: Feb. 03, 2025
-
5.5
MEDIUMCVE-2015-7847
Huawei MBB (Mobile Broadband) product E3272s with software versions earlier than E3272s-153TCPU-V200R002B491D09SP00C00 has a Denial of Service (DoS) vulnerability. An attacker could send a malicious packet to the Common Gateway Interface (CGI) of a target... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2021-0309
In onCreate of grantCredentialsPermissionActivity, there is a confused deputy. This could lead to local information disclosure and account access with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android... Read more
Affected Products : android- Published: Jan. 11, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2015-7731
SAP Mobile Platform 3.0 SP05 ClientHub allows attackers to obtain the keystream and other sensitive information via the DataVault, aka SAP Security Note 2094830.... Read more
Affected Products : mobile_platform- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0256
A sensitive information disclosure vulnerability in the mosquitto message broker of Juniper Networks Junos OS may allow a locally authenticated user with shell access the ability to read portions of sensitive files, such as the master.passwd file. Since m... Read more
Affected Products : junos- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024