Latest CVE Feed
-
5.5
MEDIUMCVE-2024-41751
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security to manipulate data.... Read more
Affected Products : smartcloud_analytics_log_analysis- Published: Jul. 23, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2020-21680
A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pict2e format.... Read more
Affected Products : fig2dev- EPSS Score: %0.27
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-54537
In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots... Read more
Affected Products : teamcity- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-54538
In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command... Read more
Affected Products : teamcity- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2022-48965
In the Linux kernel, the following vulnerability has been resolved: gpio/rockchip: fix refcount leak in rockchip_gpiolib_register() The node returned by of_get_parent() with refcount incremented, of_node_put() needs be called when finish using it. So ad... Read more
Affected Products : linux_kernel- Published: Oct. 21, 2024
- Modified: Oct. 25, 2024
-
5.5
MEDIUMCVE-2020-36787
In the Linux kernel, the following vulnerability has been resolved: media: aspeed: fix clock handling logic Video engine uses eclk and vclk for its clock sources and its reset control is coupled with eclk so the current clock enabling sequence works lik... Read more
Affected Products : linux_kernel- Published: Feb. 28, 2024
- Modified: Dec. 11, 2024
-
5.5
MEDIUMCVE-2019-3573
In libsixel v1.8.2, there is an infinite loop in the function sixel_decode_raw_impl() in the file fromsixel.c, as demonstrated by sixel2png.... Read more
Affected Products : libsixel- EPSS Score: %0.16
- Published: Jan. 02, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-8017
In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.... Read more
Affected Products : tika- EPSS Score: %3.65
- Published: Sep. 19, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-6536
An issue was discovered in Icinga 2.x through 2.8.1. The daemon creates an icinga2.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for icinga... Read more
Affected Products : icinga- EPSS Score: %0.03
- Published: Feb. 02, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-19889
An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Audio Coder (FAAC) 1.29.9.2. The vulnerability causes a segmentation fault and application crash, which leads to denial of service in the ... Read more
Affected Products : freeware_advanced_audio_coder- EPSS Score: %0.16
- Published: Dec. 06, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-19843
opmov in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (buffer over-read) via crafted x86 assembly data, as demonstrated by rasm2.... Read more
Affected Products : radare2- EPSS Score: %0.16
- Published: Dec. 04, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-19761
There is an illegal address access at fromsixel.c (function: sixel_decode_raw_impl) in libsixel 1.8.2 that will cause a denial of service.... Read more
Affected Products : libsixel- EPSS Score: %0.15
- Published: Nov. 30, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11384
The sh_op() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted ELF file.... Read more
Affected Products : radare2- EPSS Score: %0.25
- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11382
The _inst__sts() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.... Read more
Affected Products : radare2- EPSS Score: %0.23
- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-9130
The faacEncOpen function in libfaac/frame.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted wav file.... Read more
Affected Products : freeware_advanced_audio_coder- EPSS Score: %1.34
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9129
The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (large loop) via a crafted wav file.... Read more
Affected Products : freeware_advanced_audio_coder- EPSS Score: %0.82
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8906
An integer underflow vulnerability exists in pixel-a.asm, the x86 assembly code for planeClipAndMax() in MulticoreWare x265 through 2.4, as used by the x265_encoder_encode dependency in libbpg and other products. A small picture can cause an integer under... Read more
- EPSS Score: %0.28
- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8053
PoDoFo 0.9.5 allows denial of service (infinite recursion and stack consumption) via a crafted PDF file in PoDoFo::PdfParser::ReadDocumentStructure (PdfParser.cpp).... Read more
Affected Products : podofo- EPSS Score: %0.35
- Published: Apr. 22, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7946
The get_relocs_64 function in libr/bin/format/mach0/mach0.c in radare2 1.3.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted Mach0 file.... Read more
Affected Products : radare2- EPSS Score: %0.21
- Published: Apr. 18, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6846
The GraphicsStack::TGraphicsStackElement::SetNonStrokingColorSpace function in graphicsstack.h in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.... Read more
Affected Products : podofo- EPSS Score: %0.40
- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025