Latest CVE Feed
-
5.5
MEDIUMCVE-2023-46928
GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_media_change_pl /afltest/gpac/src/media_tools/isom_tools.c:3293:42.... Read more
Affected Products : gpac- EPSS Score: %0.08
- Published: Nov. 01, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-6231
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to read restricted memory.... Read more
- EPSS Score: %0.36
- Published: Mar. 05, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-32012
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 1 of 2).... Read more
- EPSS Score: %0.21
- Published: Jul. 19, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-3868
Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider backend could hijack user’s browser session.... Read more
Affected Products : keycloak- EPSS Score: %0.29
- Published: Apr. 24, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-46835
The current setup of the quarantine page tables assumes that the quarantine domain (dom_io) has been initialized with an address width of DEFAULT_DOMAIN_ADDRESS_WIDTH (48) and hence 4 page table levels. However dom_io being a PV domain gets the AMD-Vi IO... Read more
Affected Products : xen- EPSS Score: %0.08
- Published: Jan. 05, 2024
- Modified: Jun. 17, 2025
-
5.5
MEDIUMCVE-2023-52825
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix a race condition of vram buffer unref in svm code prange->svm_bo unref can happen in both mmu callback and a callback after migrate to system ram. Both are async call in... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Apr. 02, 2025
-
5.5
MEDIUMCVE-2019-2228
In array_find of array.c, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local information disclosure in the printer spooler with no additional execution privileges needed. User interaction is not needed for ex... Read more
Affected Products : android- EPSS Score: %0.10
- Published: Dec. 06, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-31914
Jerryscript 3.0 (commit 05dbbd1) was discovered to contain out-of-memory issue in malloc.... Read more
Affected Products : jerryscript- EPSS Score: %0.04
- Published: May. 12, 2023
- Modified: Jan. 24, 2025
-
5.5
MEDIUMCVE-2022-35670
Adobe Acrobat Reader versions 22.001.20169 (and earlier), 20.005.30362 (and earlier) and 17.012.30249 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerabi... Read more
- EPSS Score: %0.17
- Published: Aug. 11, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-18849
In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.... Read more
- EPSS Score: %0.77
- Published: Nov. 11, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-17349
An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a LoadExcl or StoreExcl operation.... Read more
- EPSS Score: %0.14
- Published: Oct. 08, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-52650
In the Linux kernel, the following vulnerability has been resolved: drm/tegra: dsi: Add missing check for of_find_device_by_node Add check for the return value of of_find_device_by_node() and return the error if it fails in order to avoid NULL pointer d... Read more
- Published: May. 01, 2024
- Modified: Dec. 23, 2024
-
5.5
MEDIUMCVE-2023-52811
In the Linux kernel, the following vulnerability has been resolved: scsi: ibmvfc: Remove BUG_ON in the case of an empty event pool In practice the driver should never send more commands than are allocated to a queue's event pool. In the unlikely event t... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Apr. 02, 2025
-
5.5
MEDIUMCVE-2019-1474
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1472.... Read more
- EPSS Score: %1.62
- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-46362
jbig2enc v0.28 was discovered to contain a heap-use-after-free via jbig2enc_auto_threshold_using_hash in src/jbig2enc.cc.... Read more
Affected Products : jbig2enc- EPSS Score: %0.08
- Published: Nov. 08, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-46343
In the Linux kernel before 6.5.9, there is a NULL pointer dereference in send_acknowledge in net/nfc/nci/spi.c.... Read more
Affected Products : linux_kernel- EPSS Score: %0.01
- Published: Jan. 23, 2024
- Modified: Jun. 17, 2025
-
5.5
MEDIUMCVE-2023-46332
WebAssembly wabt 1.0.33 contains an Out-of-Bound Memory Write in DataSegment::Drop(), which lead to segmentation fault.... Read more
Affected Products : webassembly_binary_toolkit- EPSS Score: %0.05
- Published: Oct. 23, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-1381
An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locations, aka 'Microsoft Windows Information Disclosure Vulnerability'.... Read more
- EPSS Score: %1.06
- Published: Nov. 12, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-1345
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1334.... Read more
- EPSS Score: %7.94
- Published: Oct. 10, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-46246
Vim is an improved version of the good old UNIX editor Vi. Heap-use-after-free in memory allocated in the function `ga_grow_inner` in in the file `src/alloc.c` at line 748, which is freed in the file `src/ex_docmd.c` in the function `do_cmdline` at line 1... Read more
Affected Products : vim- EPSS Score: %0.01
- Published: Oct. 27, 2023
- Modified: Feb. 13, 2025