Latest CVE Feed
-
5.5
MEDIUMCVE-2020-1419
An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1367, CVE-2020-1389, CVE-2020-1426.... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_server windows +1 more products- Published: Jul. 14, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-2198
QEMU (aka Quick Emulator) built with the USB EHCI emulation support is vulnerable to a null pointer dereference flaw. It could occur when an application attempts to write to EHCI capabilities registers. A privileged user inside quest could use this flaw t... Read more
- Published: Dec. 29, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2014-4806
The installation process in IBM Security AppScan Enterprise 8.x before 8.6.0.2 iFix 003, 8.7.x before 8.7.0.1 iFix 003, 8.8.x before 8.8.0.1 iFix 002, and 9.0.x before 9.0.0.1 iFix 001 on Linux places a cleartext password in a temporary file, which allows... Read more
- Published: Aug. 29, 2014
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2020-36431
Unicorn Engine 1.0.2 has an out-of-bounds write in helper_wfe_arm.... Read more
Affected Products : unicorn_engine- Published: Jul. 20, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-36427
GNOME gThumb before 3.10.1 allows an application crash via a malformed JPEG image.... Read more
Affected Products : gthumb- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-29785
In aur_get_state of aurora.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Jun. 13, 2024
- Modified: Mar. 18, 2025
-
5.5
MEDIUMCVE-2014-4660
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a f... Read more
Affected Products : ansible- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-4659
Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.... Read more
Affected Products : ansible- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-36375
Stack overflow vulnerability in parse_equality Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.... Read more
Affected Products : mjs- Published: May. 28, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-36374
Stack overflow vulnerability in parse_comparison Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.... Read more
Affected Products : mjs- Published: May. 28, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-29745
there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Actively Exploited
- Published: Apr. 05, 2024
- Modified: Jul. 30, 2025
-
5.5
MEDIUMCVE-2020-36373
Stack overflow vulnerability in parse_shifts Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.... Read more
Affected Products : mjs- Published: May. 28, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-36312
An issue was discovered in the Linux kernel before 5.8.10. virt/kvm/kvm_main.c has a kvm_io_bus_unregister_dev memory leak upon a kmalloc failure, aka CID-f65886606c2d.... Read more
Affected Products : linux_kernel- Published: Apr. 07, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-35858
In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix memory leak when bringing down interface When bringing down the TX rings we flush the rings but forget to reclaimed the flushed packets. This leads to a memory leak sin... Read more
Affected Products : linux_kernel- Published: May. 17, 2024
- Modified: Dec. 30, 2024
-
5.5
MEDIUMCVE-2020-36241
autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the inten... Read more
- Published: Feb. 05, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-11550
The id3_ucs4_length function in ucs4.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (NULL Pointer Dereference and application crash) via a crafted mp3 file.... Read more
Affected Products : libid3tag- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2014-4260
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier, and 5.6.17 and earlier, allows remote authenticated users to affect integrity and availability via vectors related to SRCHAR.... Read more
- Published: Jul. 17, 2014
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2020-36311
An issue was discovered in the Linux kernel before 5.9. arch/x86/kvm/svm/sev.c allows attackers to cause a denial of service (soft lockup) by triggering destruction of a large SEV VM (which requires unregistering many encrypted regions), aka CID-7be74942f... Read more
- Published: Apr. 07, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-16648
In Artifex MuPDF 1.13.0, the fz_append_byte function in fitz/buffer.c allows remote attackers to cause a denial of service (segmentation fault) via a crafted pdf file. This is caused by a pdf/pdf-device.c pdf_dev_alpha array-index underflow.... Read more
Affected Products : mupdf- Published: Sep. 06, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-4229
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.2, 6.3, 6.3.1, 6.3.2, 6.3.3, and 6.3.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors relate... Read more
Affected Products : supply_chain_products_suite- Published: Jul. 17, 2014
- Modified: Apr. 12, 2025