Latest CVE Feed
-
5.5
MEDIUMCVE-2018-1091
In the flush_tmregs_to_thread function in arch/powerpc/kernel/ptrace.c in the Linux kernel before 4.13.5, a guest kernel crash can be triggered from unprivileged userspace during a core dump on a POWER host due to a missing processor feature check and an ... Read more
Affected Products : linux_kernel- EPSS Score: %0.05
- Published: Mar. 27, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-10862
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.... Read more
Affected Products : enterprise_linux virtualization jboss_enterprise_application_platform wildfly_core- EPSS Score: %0.32
- Published: Jul. 27, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2012-3361
virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.... Read more
- EPSS Score: %1.38
- Published: Jul. 22, 2012
- Modified: Apr. 11, 2025
-
5.5
MEDIUMCVE-2018-1000801
okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that can result in Arbitrary file creation on the user workstation. This attack appear to be exploitable via he v... Read more
- EPSS Score: %2.28
- Published: Sep. 06, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-0968
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure Vulnerabilit... Read more
- EPSS Score: %2.61
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-13672
QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update.... Read more
- EPSS Score: %0.56
- Published: Sep. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2023-48349
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed... Read more
- EPSS Score: %0.01
- Published: Jan. 18, 2024
- Modified: Jun. 20, 2025
-
5.5
MEDIUMCVE-2018-0360
ClamAV before 0.100.1 has an HWP integer overflow with a resultant infinite loop via a crafted Hangul Word Processor file. This is in parsehwp3_paragraph() in libclamav/hwp.c.... Read more
- EPSS Score: %0.53
- Published: Jul. 16, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-9847
The bdecode function in bdecode.cpp in libtorrent 1.1.3 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.... Read more
Affected Products : libtorrent- EPSS Score: %0.19
- Published: Jun. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9503
QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving megasas command... Read more
- EPSS Score: %0.07
- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8934
PCManFM 1.2.5 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (application unavailability).... Read more
Affected Products : pcmanfm- EPSS Score: %0.14
- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8806
The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, which ... Read more
- EPSS Score: %0.16
- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8710
The Microsoft Common Console Document (.msc) in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1 allows an attacker to read arbitrary files via an XML external entity (XXE) declaration, due to the way that the Microsoft Common Console Document ... Read more
- EPSS Score: %33.10
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8693
The Microsoft Graphics Component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability in the way it handles objects in memory, aka "Microsoft Graphics Information Disclosure Vulnerabili... Read more
- EPSS Score: %6.19
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8679
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vuln... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016- EPSS Score: %6.19
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8678
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vuln... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016- EPSS Score: %20.35
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8564
Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016- EPSS Score: %22.93
- Published: Jul. 11, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8493
Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to set variables that are either read-only or require authentication when Windows fails to enforce case sens... Read more
- EPSS Score: %0.53
- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8314
Directory Traversal in Zip Extraction built-in function in Kodi 17.1 and earlier allows arbitrary file write on disk via a Zip file as subtitles.... Read more
- EPSS Score: %6.92
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8313
Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process via a crafted subtitles file.... Read more
Affected Products : vlc_media_player- EPSS Score: %0.32
- Published: May. 23, 2017
- Modified: Apr. 20, 2025