Latest CVE Feed
-
5.5
MEDIUMCVE-2020-19609
Artifex MuPDF before 1.18.0 has a heap based buffer over-write in tiff_expand_colormap() function when parsing TIFF files allowing attackers to cause a denial of service.... Read more
- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-34491
Win32k Information Disclosure Vulnerability... Read more
Affected Products : windows_10 windows_8.1 windows_rt_8.1 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_20h2 windows_10_1507 +5 more products- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-34321
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The VisDraw.dll library in affected applications lacks proper validation of user-supplied data when parsing J2K files. This could result ... Read more
- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-19470
An issue has been found in function DCTStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a NULL pointer dereference (invalid read of size 1) .... Read more
Affected Products : pdf2json- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-19481
An issue was discovered in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid memory read in gf_m2ts_process_pmt in media_tools/mpegts.c that can cause a denial of service via a crafted MP4 file.... Read more
Affected Products : gpac- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-16302
A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.... Read more
- Published: Aug. 13, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-19473
An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an uncaught floating point exception.... Read more
Affected Products : pdf2json- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-19469
An issue has been found in function DCTStream::reset in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid write of size 8 .... Read more
Affected Products : pdf2json- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-19466
An issue has been found in function DCTStream::transformDataUnit in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid read of size 1 .... Read more
Affected Products : pdf2json- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-19464
An issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow .... Read more
Affected Products : pdf2json- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-20105
A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 1... Read more
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-15926
Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.... Read more
- Published: Oct. 12, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-52560
In the Linux kernel, the following vulnerability has been resolved: mm/damon/vaddr-test: fix memory leak in damon_do_test_apply_three_regions() When CONFIG_DAMON_VADDR_KUNIT_TEST=y and making CONFIG_DEBUG_KMEMLEAK=y and CONFIG_DEBUG_KMEMLEAK_AUTO_SCAN=y... Read more
Affected Products : linux_kernel- Published: Mar. 02, 2024
- Modified: Dec. 11, 2024
-
5.5
MEDIUMCVE-2020-15358
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.... Read more
Affected Products : ubuntu_linux outside_in_technology mysql macos enterprise_manager_ops_center sinec_ins sinec_infrastructure_network_services communications_cloud_native_core_policy iphone_os tvos +7 more products- Published: Jun. 27, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-18971
Stack-based Buffer Overflow in PoDoFo v0.9.6 allows attackers to cause a denial of service via the component 'src/base/PdfDictionary.cpp:65'.... Read more
Affected Products : podofo- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2011-3528
Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 8.9 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to eProfile.... Read more
Affected Products : peoplesoft_products- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
5.5
MEDIUMCVE-2020-18781
Heap buffer overflow vulnerability in FilePOSIX::read in File.cpp in audiofile 0.3.6 may cause denial-of-service via a crafted wav file, this bug can be triggered by the executable sfconvert.... Read more
Affected Products : audiofile- Published: Aug. 22, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-18770
An issue was discovered in function zzip_disk_entry_to_file_header in mmapped.c in zziplib 0.13.69, which will lead to a denial-of-service.... Read more
- Published: Aug. 22, 2023
- Modified: Jul. 10, 2025
-
5.5
MEDIUMCVE-2011-3527
Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Candidate Gateway.... Read more
- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
5.5
MEDIUMCVE-2011-3477
GEAR Software CD DVD Filter driver (aka GEARAspiWDM.sys), as used in Symantec Backup Exec System Recovery 8.5 and BESR 2010, Symantec System Recovery 2011, Norton 360, and Norton Ghost, allows local users to cause a denial of service (system crash) via un... Read more
- Published: Feb. 19, 2018
- Modified: Nov. 21, 2024