Latest CVE Feed
-
5.5
MEDIUMCVE-2023-33912
In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges... Read more
- Published: Aug. 07, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-31693
VMware Tools for Windows (12.x.y prior to 12.1.5, 11.x.y and 10.x.y) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user privileges in the Windows guest OS, where VMware Tools is installed, can trigger a PANI... Read more
- Published: Jun. 07, 2023
- Modified: Jan. 07, 2025
-
5.5
MEDIUMCVE-2023-33891
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.... Read more
- Published: Jul. 12, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-31618
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a null pointer, which may lead to denial of service.... Read more
Affected Products : virtual_gpu- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-3146
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the fil... Read more
- Published: Mar. 23, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-33916
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges... Read more
- Published: Sep. 04, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-3110
An issue was discovered in the Linux kernel through 5.16-rc6. _rtw_init_xmit_priv in drivers/staging/r8188eu/core/rtw_xmit.c lacks check of the return value of rtw_alloc_hwxmits() and will cause the null pointer dereference.... Read more
Affected Products : linux_kernel- Published: Dec. 14, 2022
- Modified: Apr. 22, 2025
-
5.5
MEDIUMCVE-2022-30775
xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the pdftoppm binary. It is most easily reproduced with the DCMAKE_CXX_COMPILER=afl-clang-fast++ option.... Read more
Affected Products : xpdf- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-30673
Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Ex... Read more
- Published: Sep. 16, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-33461
iniparser v4.1 is vulnerable to NULL Pointer Dereference in function iniparser_getlongint which misses check NULL for function iniparser_getstring's return.... Read more
Affected Products : iniparser- Published: Jun. 01, 2023
- Modified: Jan. 09, 2025
-
5.5
MEDIUMCVE-2020-15649
Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actually files picked. *Note: This issue only affected Firefox for Android. Other operating systems are unaffec... Read more
- Published: Aug. 10, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-28855
Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Ex... Read more
- Published: Sep. 16, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-33304
A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass system protections via the use of static credentials.... Read more
Affected Products : forticlient- Published: Nov. 14, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-33251
When Akka HTTP before 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has too weak permissions: it is readable by other users on Linux or UNIX, a similar issue to CVE-2022-41946.... Read more
- Published: May. 21, 2023
- Modified: Jan. 31, 2025
-
5.5
MEDIUMCVE-2022-28191
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where uncontrolled resource consumption can be triggered by an unprivileged regular user, which may lead to denial of service.... Read more
Affected Products : virtual_gpu- Published: May. 17, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-33196
Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7. ... Read more
Affected Products : craft_cms- Published: May. 26, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-33202
Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates, PKCS8 encoded keys, and P... Read more
- Published: Nov. 23, 2023
- Modified: Aug. 18, 2025
-
5.5
MEDIUMCVE-2022-27135
xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to cause a Denial of Service (Segmentation fault) or other unspecified effects by sending a crafted PDF file to the pdftoppm binary.... Read more
Affected Products : xpdf- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-1505
An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To expl... Read more
- Published: Aug. 17, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-1500
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request ... Read more
- Published: Aug. 17, 2020
- Modified: Nov. 21, 2024