Latest CVE Feed
-
5.5
MEDIUMCVE-2018-12867
Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.... Read more
- Published: Oct. 12, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-12845
Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.... Read more
- Published: Oct. 12, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-7268
MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information exposure vulnerability in which a local unprivileged user is able to read any root (uid 0) owned file on the system, regardless of the f... Read more
- Published: May. 21, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-39495
PDF-XChange Editor readFileIntoStream Exposed Dangerous Function Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is requir... Read more
- Published: May. 03, 2024
- Modified: May. 19, 2025
-
5.5
MEDIUMCVE-2018-7273
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables using printk calls within the function show_floppy in drivers/block/floppy.c. An attacker can read this information from dmesg and use the... Read more
Affected Products : linux_kernel- Published: Feb. 21, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-39562
GPAC v2.3-DEV-rev449-g5948e4f70-master was discovered to contain a heap-use-after-free via the gf_bs_align function at bitstream.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.... Read more
Affected Products : gpac- Published: Aug. 28, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11255
An issue was discovered in PoDoFo 0.9.5. The function PdfPage::GetPageNumber() in PdfPage.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.... Read more
Affected Products : podofo- Published: May. 18, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-10862
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.... Read more
Affected Products : enterprise_linux virtualization jboss_enterprise_application_platform wildfly_core- Published: Jul. 27, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-7174
An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams.... Read more
Affected Products : xpdf- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-7173
A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding.... Read more
Affected Products : xpdf- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2012-3361
virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.... Read more
- Published: Jul. 22, 2012
- Modified: Apr. 11, 2025
-
5.5
MEDIUMCVE-2018-1000801
okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that can result in Arbitrary file creation on the user workstation. This attack appear to be exploitable via he v... Read more
- Published: Sep. 06, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-7100
A potential security vulnerability has been identified in HPE OfficeConnect 1810 Switch Series (HP 1810-24G - P.2.22 and previous versions, HP 1810-48G PK.1.34 and previous versions, HP 1810-8 v2 P.2.22 and previous versions). The vulnerability could allo... Read more
- Published: Aug. 14, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-7099
A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-4.4.0.GA-110(MU7). The vulnerability may be locally exploited to allow disclosure of privileged information.... Read more
- Published: Aug. 14, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-7094
A security vulnerability was identified in 3PAR Service Processor (SP) prior to SP-5.0.0.0-22913(GA). The vulnerability may be exploited locally to allow disclosure of privileged information.... Read more
Affected Products : 3par_service_provider- Published: Aug. 14, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-0360
ClamAV before 0.100.1 has an HWP integer overflow with a resultant infinite loop via a crafted Hangul Word Processor file. This is in parsehwp3_paragraph() in libclamav/hwp.c.... Read more
- Published: Jul. 16, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-7073
A local arbitrary file modification vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.... Read more
- Published: Aug. 06, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-6963
VMware Workstation (14.x before 14.1.2) and Fusion (10.x before 10.1.2) contain multiple denial-of-service vulnerabilities that occur due to NULL pointer dereference issues in the RPC handler. Successful exploitation of these issues may allow an attacker ... Read more
- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-8934
PCManFM 1.2.5 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (application unavailability).... Read more
Affected Products : pcmanfm- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8806
The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, which ... Read more
- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025