Latest CVE Feed
-
5.5
MEDIUMCVE-2014-3399
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.2(.2.4) and earlier does not properly manage session information during creation of a SharePoint handler, which allows remote authenticated users to overwrite arbitrary RAMFS... Read more
Affected Products : adaptive_security_appliance_software- Published: Oct. 07, 2014
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2014-3317
Directory traversal vulnerability in the Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager 10.0(1) allows remote authenticated users to delete arbitrary files via a crafted URL, aka Bug ID CSCup76314.... Read more
Affected Products : unified_communications_manager- Published: Jul. 14, 2014
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2014-3292
The Real Time Monitoring Tool (RTMT) implementation in Cisco Unified Communications Manager (Unified CM) allows remote authenticated users to (1) read or (2) delete arbitrary files via a crafted URL, aka Bug IDs CSCuo17302 and CSCuo17199.... Read more
Affected Products : unified_communications_manager- Published: Jun. 10, 2014
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2011-2498
The Linux kernel from v2.3.36 before v2.6.39 allows local unprivileged users to cause a denial of service (memory consumption) by triggering creation of PTE pages.... Read more
- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2007-6716
fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.... Read more
- Published: Sep. 04, 2008
- Modified: Apr. 09, 2025
-
5.5
MEDIUMCVE-2016-10267
LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tif_ojpeg.c:816:8.... Read more
Affected Products : libtiff- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-1581
LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data from arbitrary containers via unspecified vectors.... Read more
- Published: Jun. 09, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-3183
The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg2000 file.... Read more
Affected Products : openjpeg- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-3597
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 5.0.26 allows local users to affect availability via vectors related to Core.... Read more
Affected Products : vm_virtualbox- Published: Jul. 21, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2020-2715
Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core). Supported versions that are affected are 12.3.0-12.4.0 and 14.0.0-14.3.0. Easily exploitable vulnerability allows low privileged att... Read more
Affected Products : banking_corporate_lending- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-3088
stconf.nsf in IBM Sametime Meeting Server 8.5.1 relies on the client to validate the file format used in wAttach?OpenForm multipart/form-data POST requests, which allows remote authenticated users to bypass intended upload restrictions by modifying the Co... Read more
Affected Products : sametime_meeting_server- Published: Jul. 01, 2014
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-5825
The icalparser_parse_string function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted ics file.... Read more
Affected Products : libical- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2014-9844
The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.... Read more
- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2014-3646
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.... Read more
Affected Products : linux_kernel ubuntu_linux enterprise_linux debian_linux suse_linux_enterprise_server evergreen- Published: Nov. 10, 2014
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-6911
The dynamicGetbuf function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TIFF image.... Read more
Affected Products : libgd- Published: Jan. 26, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-1000249
An issue in file() was introduced in commit 9611f31313a93aa036389c5f3b15eea53510d4d1 (Oct 2016) lets an attacker overwrite a fixed 20 bytes stack buffer with a specially crafted .notes section in an ELF binary. This was fixed in commit 35c94dc6acc418f1ad7... Read more
Affected Products : file- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2014-9811
The xwd file handler in ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a malformed xwd file.... Read more
Affected Products : imagemagick- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11423
The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted CAB file.... Read more
- Published: Jul. 18, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2020-2204
A missing permission check in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to the globally configured Fortify on Demand endpoint using attacker-specified credentials IDs.... Read more
Affected Products : fortify_on_demand- Published: Jul. 02, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-14121
The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer dereference flaw triggered by a crafted RAR archive. NOTE: this may be the same as one of the several test cases in the CVE-2017-11189 referen... Read more
- Published: Sep. 03, 2017
- Modified: Apr. 20, 2025