Latest CVE Feed
-
5.5
MEDIUMCVE-2024-23260
This issue was addressed by removing additional entitlements. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data.... Read more
Affected Products : macos- Published: Mar. 08, 2024
- Modified: Dec. 06, 2024
-
5.5
MEDIUMCVE-2024-50198
In the Linux kernel, the following vulnerability has been resolved: iio: light: veml6030: fix IIO device retrieval from embedded device The dev pointer that is received as an argument in the in_illuminance_period_available_show function references the d... Read more
Affected Products : linux_kernel- Published: Nov. 08, 2024
- Modified: Nov. 29, 2024
-
5.5
MEDIUMCVE-2022-49316
In the Linux kernel, the following vulnerability has been resolved: NFSv4: Don't hold the layoutget locks across multiple RPC calls When doing layoutget as part of the open() compound, we have to be careful to release the layout locks before we can call... Read more
Affected Products : linux_kernel- Published: Feb. 26, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Race Condition
-
5.5
MEDIUMCVE-2024-44988
In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: Fix out-of-bound access If an ATU violation was caused by a CPU Load operation, the SPID could be larger than DSA_MAX_PORTS (the size of mv88e6xxx_chip.ports[] arra... Read more
Affected Products : linux_kernel- Published: Sep. 04, 2024
- Modified: Nov. 08, 2024
-
5.5
MEDIUMCVE-2024-35828
In the Linux kernel, the following vulnerability has been resolved: wifi: libertas: fix some memleaks in lbs_allocate_cmd_buffer() In the for statement of lbs_allocate_cmd_buffer(), if the allocation of cmdarray[i].cmdbuf fails, both cmdarray and cmdarr... Read more
- Published: May. 17, 2024
- Modified: Jan. 14, 2025
-
5.5
MEDIUMCVE-2020-27194
An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or in kernel/bpf/verifier.c mishandles bounds tracking during use of 64-bit values, aka CID-5b9fbeb75b6a.... Read more
Affected Products : linux_kernel- Published: Oct. 16, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-4471
The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token... Read more
Affected Products : horizon- Published: May. 14, 2014
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2014-9818
ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a malformed sun file.... Read more
Affected Products : imagemagick- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2013-4320
The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.9 and 6.1.x before 6.1.4 does not properly check permissions, which allows remote authenticated users to create or read arbitrary files via a crafted URL.... Read more
Affected Products : typo3- Published: May. 20, 2014
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2022-49729
In the Linux kernel, the following vulnerability has been resolved: nfc: nfcmrvl: Fix memory leak in nfcmrvl_play_deferred Similar to the handling of play_deferred in commit 19cfe912c37b ("Bluetooth: btusb: Fix memory leak in play_deferred"), we thought... Read more
Affected Products : linux_kernel- Published: Feb. 26, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2020-27152
An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to improper interaction between a resampler and edge triggering, aka CID-77377064c3a9.... Read more
Affected Products : linux_kernel- Published: Nov. 06, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-4281
In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file.... Read more
Affected Products : openshift- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
5.5
MEDIUMCVE-2020-27098
In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible way to access contacts due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not nee... Read more
Affected Products : android- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-27097
In checkGrantUriPermission of UriGrantsManagerService.java, there is a possible permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An... Read more
Affected Products : android- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-4176
mysecureshell 1.31: Local Information Disclosure Vulnerability... Read more
Affected Products : mysecureshell- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-4175
MySecureShell 1.31 has a Local Denial of Service Vulnerability... Read more
Affected Products : mysecureshell- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-38449
Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigati... Read more
- Published: Oct. 14, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-27146
GPAC mp4box 1.1.0-DEV-rev1759-geb2d1e6dd-has a heap-buffer-overflow vulnerability in function gf_isom_apple_enum_tag.... Read more
Affected Products : gpac- Published: Apr. 08, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2010-0207
In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers.... Read more
- Published: Oct. 30, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-27039
In postNotification of ServiceRecord.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product... Read more
Affected Products : android- Published: Dec. 15, 2020
- Modified: Nov. 21, 2024