Latest CVE Feed
-
5.5
MEDIUMCVE-2020-8566
In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during provisioning of Ceph RBD persistent claims. This affects ... Read more
Affected Products : kubernetes- Published: Dec. 07, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-28178
A logic issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, macOS Monterey 12.6.4, tvOS 16.4, watchOS 9.4. An app may be able to bypass Privacy preferences.... Read more
- Published: May. 08, 2023
- Modified: Jan. 29, 2025
-
5.5
MEDIUMCVE-2005-1879
LutelWall 0.97 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.... Read more
Affected Products : lutelwall- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2023-28147
An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Midgard r29p0 through r32p0, Bifrost r17p0 through r42p0 before r43p0, Valhal... Read more
- Published: Jun. 02, 2023
- Modified: Jan. 09, 2025
-
5.5
MEDIUMCVE-2023-27948
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3. Processing an image may result in disclosure of process memory.... Read more
Affected Products : macos- Published: Aug. 14, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-35983
This issue was addressed with improved data protection. This issue is fixed in macOS Monterey 12.6.8, macOS Ventura 13.5, macOS Big Sur 11.7.9. An app may be able to modify protected parts of the file system.... Read more
Affected Products : macos- Published: Jul. 27, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-2662
In Xpdf 4.04 (and earlier), a bad color space object in the input PDF file can cause a divide-by-zero. ... Read more
Affected Products : xpdf- Published: May. 11, 2023
- Modified: Jan. 24, 2025
-
5.5
MEDIUMCVE-2023-26377
Adobe Dimension version 3.4.8 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue ... Read more
- Published: Apr. 12, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-26376
Adobe Dimension version 3.4.8 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue ... Read more
- Published: Apr. 12, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-26353
Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue... Read more
Affected Products : dimension- Published: Mar. 28, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-26351
Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue... Read more
Affected Products : dimension- Published: Mar. 28, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-26345
Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue... Read more
Affected Products : dimension- Published: Mar. 28, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-24755
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.... Read more
- Published: Mar. 01, 2023
- Modified: Mar. 07, 2025
-
5.5
MEDIUMCVE-2023-23506
A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.2. An app may be able to access user-sensitive data.... Read more
Affected Products : macos- Published: Feb. 27, 2023
- Modified: Mar. 11, 2025
-
5.5
MEDIUMCVE-2023-23005
In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic c... Read more
- Published: Mar. 01, 2023
- Modified: Mar. 19, 2025
-
5.5
MEDIUM- Published: Feb. 14, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-35789
An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command line (e.g., for amqp-publish or amqp-consume) and are thus visible to local attackers by listing a process an... Read more
Affected Products : rabbitmq-c- Published: Jun. 16, 2023
- Modified: Mar. 30, 2025
-
5.5
MEDIUMCVE-2023-21584
FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of ... Read more
- Published: Feb. 17, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-3634
Parameter corruption in NDIS filter driver in Intel Online Connect Access 1.9.22.0 allows an attacker to cause a denial of service via local access.... Read more
Affected Products : online_connect_access- Published: May. 15, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-35890
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security, caused by the improper encoding in a local configuration file. IBM X-Force ID: 258637.... Read more
Affected Products : websphere_application_server- Published: Jul. 07, 2023
- Modified: Nov. 21, 2024