Latest CVE Feed
-
5.5
MEDIUMCVE-2009-3630
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to place arbitrary web sites in TYPO3 backend framesets via crafted parameters, related to a "frame... Read more
Affected Products : typo3- EPSS Score: %0.95
- Published: Nov. 02, 2009
- Modified: Apr. 09, 2025
-
5.5
MEDIUMCVE-2018-5836
In wma_nan_rsp_event_handler() in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, the data_len value is received from firmware and not properly validated which cou... Read more
Affected Products : android- EPSS Score: %0.03
- Published: Jul. 06, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-0113
Insufficient bounds checking in Intel(R) Graphics Drivers before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow an authenticated user to potentially enable a denial of service via local access.... Read more
- EPSS Score: %0.06
- Published: May. 17, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-39136
An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a crafted zip file.... Read more
Affected Products : ziparchive- EPSS Score: %0.05
- Published: Aug. 30, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-39130
GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap buffer overflow via the function pe_as16() at /gdb/coff-pe-read.c.... Read more
Affected Products : gdb- EPSS Score: %0.02
- Published: Jul. 25, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-5783
In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PoDoFo::PdfVecObjects::Reserve function (base/PdfVecObjects.h). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted pdf file.... Read more
Affected Products : podofo- EPSS Score: %0.37
- Published: Jan. 19, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-5750
The acpi_smbus_hc_add function in drivers/acpi/sbshc.c in the Linux kernel through 4.14.15 allows local users to obtain sensitive address information by reading dmesg data from an SBS HC printk call.... Read more
- EPSS Score: %0.04
- Published: Jan. 26, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-5730
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which ... Read more
- EPSS Score: %1.11
- Published: Mar. 06, 2018
- Modified: May. 05, 2025
-
5.5
MEDIUMCVE-2023-39128
GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a stack overflow via the function ada_decode at /gdb/ada-lang.c.... Read more
Affected Products : gdb- EPSS Score: %0.02
- Published: Jul. 25, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-39129
GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap use after free via the function add_pe_exported_sym() at /gdb/coff-pe-read.c.... Read more
Affected Products : gdb- EPSS Score: %0.02
- Published: Jul. 25, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-7064
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. The issue involves the "WebKit" component. It allo... Read more
- EPSS Score: %3.32
- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2006-2308
Directory traversal vulnerability in the IMAP service in EServ/3 3.25 allows remote authenticated users to read other user's email messages, create/rename arbitrary directories on the system, and delete empty directories via directory traversal sequences ... Read more
Affected Products : eserv- EPSS Score: %2.23
- Published: Jun. 02, 2006
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2017-7003
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "CoreText" component. It allows remote attackers t... Read more
- EPSS Score: %0.28
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-5309
In PoDoFo 0.9.5, there is an integer overflow in the PdfObjectStreamParserObject::ReadObjectsFromStream function (base/PdfObjectStreamParserObject.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted pdf file... Read more
Affected Products : podofo- EPSS Score: %0.23
- Published: Jan. 09, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-5268
In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file.... Read more
- EPSS Score: %0.34
- Published: Jan. 08, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-5269
In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast.... Read more
- EPSS Score: %0.50
- Published: Jan. 08, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2008-1567
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.... Read more
- EPSS Score: %0.04
- Published: Mar. 31, 2008
- Modified: Apr. 09, 2025
-
5.5
MEDIUMCVE-2018-5201
Hancom Office 2018 10.0.0.8214 and earlier, Hancom Office NEO 9.6.1.10472 and earlier, Hancom Office 2014 9.1.1.4540 and earlier, Hancom Office 2010 8.5.8.1724 and earlier versions have a heap overflow vulnerability when handling Compound File in document... Read more
- EPSS Score: %0.16
- Published: Dec. 21, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-6849
The PoDoFo::PdfColorGray::~PdfColorGray function in PdfColor.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.... Read more
Affected Products : podofo- EPSS Score: %0.20
- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6848
The PoDoFo::PdfXObject::PdfXObject function in PdfXObject.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.... Read more
Affected Products : podofo- EPSS Score: %0.40
- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025