Latest CVE Feed
-
5.5
MEDIUMCVE-2017-11434
The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) via a crafted DHCP options string.... Read more
- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2019-15924
An issue was discovered in the Linux kernel before 5.0.11. fm10k_init_module in drivers/net/ethernet/intel/fm10k/fm10k_main.c has a NULL pointer dereference because there is no -ENOMEM upon an alloc_workqueue failure.... Read more
Affected Products : linux_kernel- Published: Sep. 04, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-11171
Bad reference counting in the context of accept_ice_connection() in gsm-xsmp-server.c in old versions of gnome-session up until version 2.29.92 allows a local attacker to establish ICE connections to gnome-session with invalid authentication data (an inva... Read more
Affected Products : gnome-session- Published: Jul. 11, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-1000382
VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the vi binary.... Read more
Affected Products : vim- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9888
An error within the "tar_directory_for_file()" function (gsf-infile-tar.c) in GNOME Structured File Library before 1.14.41 can be exploited to trigger a Null pointer dereference and subsequently cause a crash via a crafted TAR file.... Read more
Affected Products : libgsf- Published: Dec. 08, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-9588
arch/x86/kvm/vmx.c in the Linux kernel through 4.9 mismanages the #BP and #OF exceptions, which allows guest OS users to cause a denial of service (guest OS crash) by declining to handle an exception thrown by an L2 guest.... Read more
Affected Products : linux_kernel- Published: Dec. 28, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-9394
The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.... Read more
Affected Products : jasper- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9393
The jpc_pi_nextrpcl function in jpc_t2cod.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.... Read more
Affected Products : jasper- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2019-14879
A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).... Read more
Affected Products : moodle- Published: Jan. 07, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-8691
The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted XRsiz value in a BMP image to the imginfo command.... Read more
- Published: Feb. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-7166
libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file.... Read more
- Published: Sep. 21, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2023-52582
In the Linux kernel, the following vulnerability has been resolved: netfs: Only call folio_start_fscache() one time for each folio If a network filesystem using netfs implements a clamp_length() function, it can set subrequest lengths smaller than a pag... Read more
Affected Products : linux_kernel- Published: Mar. 02, 2024
- Modified: Jan. 16, 2025
-
5.5
MEDIUMCVE-2016-6197
fs/overlayfs/dir.c in the OverlayFS filesystem implementation in the Linux kernel before 4.6 does not properly verify the upper dentry before proceeding with unlink and rename system-call processing, which allows local users to cause a denial of service (... Read more
- Published: Aug. 06, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-6163
The rsvg_pattern_fix_fallback function in rsvg-paint_server.c in librsvg2 2.40.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted svg file.... Read more
Affected Products : librsvg- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-5031
The print_frame_inst_bytes function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.... Read more
Affected Products : libdwarf- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2019-14662
Brandy 1.20.1 has a stack-based buffer overflow in fileio_openout in fileio.c via crafted BASIC source code.... Read more
Affected Products : brandy- Published: Aug. 05, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-14663
Brandy 1.20.1 has a stack-based buffer overflow in fileio_openin in fileio.c via crafted BASIC source code.... Read more
Affected Products : brandy- Published: Aug. 05, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-14665
Brandy 1.20.1 has a heap-based buffer overflow in define_array in variables.c via crafted BASIC source code.... Read more
Affected Products : brandy- Published: Aug. 05, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-4487
Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to "btypevec."... Read more
Affected Products : libiberty- Published: Feb. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2023-28826
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4, macOS Sonoma 14.1, macOS Ventura 13.6.5. An app may be able to access sensitive user data.... Read more
- Published: Mar. 08, 2024
- Modified: Mar. 28, 2025