Latest CVE Feed
-
5.5
MEDIUMCVE-2017-5666
The free_options function in options_manager.c in mp3splt 2.6.2 allows remote attackers to cause a denial of service (invalid free and crash) via a crafted file.... Read more
Affected Products : mp3splt- EPSS Score: %0.24
- Published: Mar. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-13666
An integer underflow vulnerability exists in pixel-a.asm, the x86 assembly code for planeClipAndMax() in MulticoreWare x265 through 2.5, as used in libbpg and other products. A small height value can cause an integer underflow, which leads to a crash. Thi... Read more
Affected Products : x265- EPSS Score: %0.10
- Published: Aug. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-8678
The IsPixelMonochrome function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.0 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted file. NOTE: the vendor says "This is a Q64 issue and we do not support ... Read more
Affected Products : imagemagick- EPSS Score: %0.21
- Published: Feb. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-7438
The C software implementation of ECC in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.... Read more
Affected Products : wolfssl- EPSS Score: %0.14
- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2015-8697
stalin 0.11-5 allows local users to write to arbitrary files.... Read more
Affected Products : stalin- EPSS Score: %0.06
- Published: Jun. 27, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2023-6039
A use-after-free flaw was found in lan78xx_disconnect in drivers/net/usb/lan78xx.c in the network sub-component, net/usb/lan78xx in the Linux Kernel. This flaw allows a local attacker to crash the system when the LAN78XX USB device detaches.... Read more
Affected Products : linux_kernel- EPSS Score: %0.01
- Published: Nov. 09, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-53099
Sentry is a developer-first error tracking and performance monitoring tool. Prior to version 25.5.0, an attacker with a malicious OAuth application registered with Sentry can take advantage of a race condition and improper handling of authorization code w... Read more
Affected Products : sentry- Published: Jul. 01, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Race Condition
-
5.5
MEDIUMCVE-2025-6017
A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. Thi... Read more
Affected Products : advanced_cluster_management_for_kubernetes- Published: Jul. 02, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2019-1472
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1474.... Read more
- EPSS Score: %1.62
- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-1464
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.... Read more
- EPSS Score: %13.32
- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-7067
A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5FS__sinfo_serialize_node_cb of the file src/H5FScache.c. The manipulation leads to heap-based buffer overflow. Local access is required to approa... Read more
Affected Products : hdf5- Published: Jul. 04, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-7069
A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FS__sect_link_size of the file src/H5FSsection.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the l... Read more
Affected Products : hdf5- Published: Jul. 04, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-7107
A vulnerability classified as critical has been found in SimStudioAI sim up to 0.1.17. Affected is the function handleLocalFile of the file apps/sim/app/api/files/parse/route.ts. The manipulation of the argument filePath leads to path traversal. It is pos... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Path Traversal
-
5.5
MEDIUMCVE-2019-1442
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vul... Read more
Affected Products : sharepoint_server- EPSS Score: %7.10
- Published: Nov. 12, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2025-20687
In Bluetooth driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418045; Issue... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-20688
In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418047; Is... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-20690
In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418038; Is... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-20691
In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418039; Is... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-20998
Improper access control in SamsungAccount for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to access phone number.... Read more
Affected Products :- Published: Jul. 08, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2024-46664
A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or HTTPs requests.... Read more
Affected Products : fortirecorder- Published: Jan. 14, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Path Traversal