Latest CVE Feed
-
5.5
MEDIUMCVE-2012-0038
Integer overflow in the xfs_acl_from_disk function in fs/xfs/xfs_acl.c in the Linux kernel before 3.1.9 allows local users to cause a denial of service (panic) via a filesystem with a malformed ACL, leading to a heap-based buffer overflow.... Read more
Affected Products : linux_kernel- Published: May. 17, 2012
- Modified: Apr. 11, 2025
-
5.5
MEDIUMCVE-2020-8632
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.... Read more
- Published: Feb. 05, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2015-6470
Resource Data Management Data Manager before 2.2 allows remote authenticated users to modify arbitrary passwords via unspecified vectors.... Read more
Affected Products : data_manager- Published: Sep. 26, 2015
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2024-35975
In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix transmit scheduler resource leak Inorder to support shaping and scheduling, Upon class creation Netdev driver allocates trasmit schedulers. The previous patch which a... Read more
Affected Products : linux_kernel- Published: May. 20, 2024
- Modified: Jan. 14, 2025
-
5.5
MEDIUMCVE-2015-6461
Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC we... Read more
Affected Products : bmxnoe0100_firmware bmxnoe0110_firmware bmxnor0200h_firmware bmxnoc0401_firmware bmxnoe0110h_firmware modicon_m340_bmxp342020_firmware modicon_m340_bmxp342030_firmware modicon_m340_bmxp342020h_firmware modicon_m340_bmxp3420302_firmware modicon_m340_bmxp3420302h_firmware +12 more products- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2011-2923
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbit... Read more
- Published: Nov. 19, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-8585
OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY Link (plink).... Read more
Affected Products : oncommand_unified_manager- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-8565
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.... Read more
Affected Products : kubernetes- Published: Dec. 07, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-8557
The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet evicti... Read more
Affected Products : kubernetes- Published: Jul. 23, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-8564
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3,... Read more
Affected Products : kubernetes- Published: Dec. 07, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2011-1489
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the... Read more
- Published: Nov. 14, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2011-1166
Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host crash) by specifying user mode execution without user-mode pagetables.... Read more
Affected Products : xen- Published: Jan. 07, 2014
- Modified: Apr. 11, 2025
-
5.5
MEDIUMCVE-2010-3079
kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properly handle interaction between mutex possession and llseek operations, which allows local users to cause a denial of service (NULL pointer dereference and ou... Read more
- Published: Sep. 30, 2010
- Modified: Apr. 11, 2025
-
5.5
MEDIUMCVE-2024-35850
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix NULL-deref on non-serdev setup Qualcomm ROME controllers can be registered from the Bluetooth line discipline and in this case the HCI UART serdev pointer is NULL. ... Read more
Affected Products : linux_kernel- Published: May. 17, 2024
- Modified: Dec. 30, 2024
-
5.5
MEDIUMCVE-2020-8346
A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 that could allow configuration files to be written to non-standard locations.... Read more
Affected Products : system_interface_foundation- Published: Sep. 15, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-8315
In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.dll being loaded and used instead of the system's copy. ... Read more
Affected Products : python- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-8175
Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using specially a crafted JPEG image.... Read more
Affected Products : jpeg-js- Published: Jul. 24, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-8092
A privilege escalation vulnerability in BDLDaemon as used in Bitdefender Antivirus for Mac allows a local attacker to obtain authentication tokens for requests submitted to the Bitdefender Cloud. This issue affects: Bitdefender Bitdefender Antivirus for M... Read more
Affected Products : antivirus- Published: Jan. 30, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-7918
An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of other users via enumeration.... Read more
Affected Products : totemomail- Published: Mar. 27, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2006-1058
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.... Read more
- Published: Apr. 04, 2006
- Modified: Apr. 03, 2025