Latest CVE Feed
-
5.5
MEDIUMCVE-2019-9213
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to exploit kernel NULL pointer dereferences on non-SMAP platforms. This is related to a capability check for ... Read more
- Published: Mar. 05, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-13938
Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows... Read more
- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-13999
ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library) 1.0.12 allows an integer overflow and denial of service via a crafted EMF file.... Read more
- Published: Jun. 15, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-14373
A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to cause a denial of service.... Read more
- Published: Sep. 03, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-14103
The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.... Read more
- Published: Apr. 08, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-6631
An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_m2ts_stream_process_pmt() in media_tools/m2ts_mux.c.... Read more
Affected Products : gpac- Published: Jan. 09, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-23527
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, macOS Big Sur 11.7.5, macOS Monterey 12.6.4, tvOS 16.4, watchOS 9.4. A user may gain access to protected parts of the file system.... Read more
- Published: May. 08, 2023
- Modified: Jan. 29, 2025
-
5.5
MEDIUMCVE-2021-1544
A vulnerability in logging mechanisms of Cisco Webex Meetings client software could allow an authenticated, local attacker to gain access to sensitive information. This vulnerability is due to unsafe logging of application actions. An attacker could explo... Read more
Affected Products : webex_meetings- Published: Jun. 04, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-18397
The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, an... Read more
- Published: Dec. 12, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-11098
The SVG Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.1.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated... Read more
Affected Products : svg_block- Published: Nov. 19, 2024
- Modified: Nov. 19, 2024
-
5.5
MEDIUMCVE-2022-1771
Uncontrolled Recursion in GitHub repository vim/vim prior to 8.2.4975.... Read more
Affected Products : vim- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-26376
Insufficient checks in System Management Unit (SMU) FeatureConfig may result in reenabling features potentially resulting in denial of resources and/or denial of service.... Read more
Affected Products : epyc_7f72_firmware epyc_7f52_firmware epyc_7f32_firmware epyc_7742_firmware epyc_7702p_firmware epyc_7702_firmware epyc_7662_firmware epyc_7642_firmware epyc_7552_firmware epyc_7542_firmware +157 more products- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-11079
A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outpu... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Dec. 18, 2024
-
5.5
MEDIUMCVE-2020-13904
FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees a pointer, and later that pointer is accessed in av_probe_input_format3 in libavformat/format.c.... Read more
- Published: Jun. 07, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-15746
qemu-seccomp.c in QEMU might allow local OS guest users to cause a denial of service (guest crash) by leveraging mishandling of the seccomp policy for threads other than the main thread.... Read more
Affected Products : qemu- Published: Aug. 29, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-34320
Cortex-A77 cores (r0p0 and r1p0) are affected by erratum 1508412 where software, under certain circumstances, could deadlock a core due to the execution of either a load to device or non-cacheable memory, and either a store exclusive or register read of t... Read more
- Published: Dec. 08, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2012-1146
The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are attached to the same eventfd, which allows local users to cause a denial of service (NULL pointer derefer... Read more
- Published: May. 17, 2012
- Modified: Apr. 11, 2025
-
5.5
MEDIUMCVE-2024-11029
A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials, including the administrator pass... Read more
Affected Products : enterprise_linux- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2019-8560
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to read restricted memory.... Read more
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2024-35968
In the Linux kernel, the following vulnerability has been resolved: pds_core: Fix pdsc_check_pci_health function to use work thread When the driver notices fw_status == 0xff it tries to perform a PCI reset on itself via pci_reset_function() in the conte... Read more
Affected Products : linux_kernel- Published: May. 20, 2024
- Modified: Jan. 14, 2025