Latest CVE Feed
-
5.5
MEDIUMCVE-2021-47170
In the Linux kernel, the following vulnerability has been resolved: USB: usbfs: Don't WARN about excessively large memory allocations Syzbot found that the kernel generates a WARNing if the user tries to submit a bulk transfer through usbfs with a buffe... Read more
Affected Products : linux_kernel- Published: Mar. 25, 2024
- Modified: Mar. 17, 2025
-
5.5
MEDIUMCVE-2023-52788
In the Linux kernel, the following vulnerability has been resolved: i915/perf: Fix NULL deref bugs with drm_dbg() calls When i915 perf interface is not available dereferencing it will lead to NULL dereferences. As returning -ENOTSUPP is pretty clear re... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Jan. 31, 2025
-
5.5
MEDIUMCVE-2024-44302
The issue was addressed with improved checks. This issue is fixed in tvOS 18.1, iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, visionOS 2.1. Processing a maliciously crafted font may result... Read more
- Published: Oct. 28, 2024
- Modified: Dec. 06, 2024
-
5.5
MEDIUMCVE-2022-37996
Windows Kernel Memory Information Disclosure Vulnerability... Read more
Affected Products : windows_10 windows_8.1 windows_rt_8.1 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_20h2 windows_10_21h2 +8 more products- EPSS Score: %0.40
- Published: Oct. 11, 2022
- Modified: Jan. 02, 2025
-
5.5
MEDIUMCVE-2020-3347
A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to gain access to sensitive information on an affected system. The vulnerability is due to unsafe usage of shared memory that is used by the affec... Read more
- EPSS Score: %0.07
- Published: Jun. 18, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-40773
Adobe Prelude version 10.1 (and earlier) is affected by a null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the contex... Read more
- EPSS Score: %0.41
- Published: Nov. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-42810
The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13. Processing a maliciously crafted USD file may disclose memory contents.... Read more
- EPSS Score: %0.07
- Published: Nov. 01, 2022
- Modified: Apr. 22, 2025
-
5.5
MEDIUMCVE-2024-7421
An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP session... Read more
Affected Products : remote_desktop_manager- Published: Sep. 25, 2024
- Modified: Mar. 17, 2025
-
5.5
MEDIUMCVE-2018-7492
A NULL pointer dereference was found in the net/rds/rdma.c __rds_rdma_map() function in the Linux kernel before 4.14.7 allowing local attackers to cause a system panic and a denial-of-service, related to RDS_GET_MR and RDS_GET_MR_FOR_DEST.... Read more
- EPSS Score: %0.08
- Published: Feb. 26, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-11095
In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.... Read more
- EPSS Score: %0.21
- Published: Jun. 22, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-2496
A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virConnectListAllInterfaces API. This fl... Read more
- Published: Mar. 18, 2024
- Modified: Apr. 09, 2025
-
5.5
MEDIUMCVE-2020-7063
In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR archive using PharData::buildFromIterator() function, the files are added with default permissions (0666, or all access) even if the original files on the fil... Read more
- EPSS Score: %0.34
- Published: Feb. 27, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-2812
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple pro... Read more
- EPSS Score: %0.46
- Published: Apr. 19, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-7728
An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileHandlers/TIFF_Handler.cpp mishandles a case of a zero length, leading to a heap-based buffer over-read in the MD5Update() function in third-party/zuid/interfaces/MD5.cpp.... Read more
- EPSS Score: %0.30
- Published: Mar. 06, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-9610
Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier have a null pointer vulnerability. Successful exploitation could lead to application denial-of-service.... Read more
- EPSS Score: %1.29
- Published: Jun. 25, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-35865
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_is_valid_oplock_break() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.... Read more
Affected Products : linux_kernel- Published: May. 19, 2024
- Modified: Apr. 07, 2025
-
5.5
MEDIUMCVE-2021-3566
Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitimate "ffconcat" file that references an image, followed by a file the triggers the tty demuxer, the contents of the second file will be c... Read more
- EPSS Score: %0.10
- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-7061
Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.... Read more
Affected Products : plone- EPSS Score: %0.26
- Published: May. 02, 2014
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2023-52938
In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: Don't attempt to resume the ports before they exist This will fix null pointer dereference that was caused by the driver attempting to resume ports that were not yet r... Read more
Affected Products : linux_kernel- Published: Mar. 27, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2020-11935
It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerability to cause a denial of service attack.... Read more
- EPSS Score: %0.03
- Published: Apr. 07, 2023
- Modified: Nov. 21, 2024