Latest CVE Feed
-
5.5
MEDIUMCVE-2018-7175
An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of service via a JPX image with zero components.... Read more
Affected Products : xpdf- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-25179
Uncontrolled resource consumption in the Intel(R) Unite(R) android application before Release 17 may allow an authenticated user to potentially enable denial of service via local access.... Read more
Affected Products : unite- Published: May. 10, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-6925
In FreeBSD before 11.2-STABLE(r338986), 11.2-RELEASE-p4, 11.1-RELEASE-p15, 10.4-STABLE(r338985), and 10.4-RELEASE-p13, due to improper maintenance of IPv6 protocol control block flags through various failure paths, an unprivileged authenticated local user... Read more
Affected Products : freebsd- Published: Sep. 28, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-5747
In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.... Read more
- Published: Jan. 17, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-5519
On F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.3, or 11.2.1-11.6.3.1, administrative users by way of undisclosed methods can exploit the ssldump utility to write to arbitrary file paths. For users who do not have Advanced Shell access (for example, any user ... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager big-ip_policy_enforcement_manager +3 more products- Published: May. 02, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-4335
A validation issue was addressed with improved input sanitization. This issue affected versions prior to iOS 12.... Read more
Affected Products : iphone_os- Published: Apr. 03, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-4255
In macOS High Sierra before 10.13.5, an out-of-bounds read was addressed with improved input validation.... Read more
- Published: Jan. 11, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-4159
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Graphics Drivers" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.... Read more
- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-4084
An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Wi-Fi" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-24862
Windows Secure Channel Denial of Service Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_20h2 windows_10_21h2 windows_10_22h2 windows_server_2022 +7 more products- Published: Mar. 14, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-24785
An issue in Giorgio Tani peazip v.9.0.0 allows attackers to cause a denial of service via the End of Archive tag function of the peazip/pea UNPEA feature.... Read more
Affected Products : peazip- Published: Feb. 17, 2023
- Modified: Mar. 18, 2025
-
5.5
MEDIUMCVE-2023-24758
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.... Read more
- Published: Mar. 01, 2023
- Modified: Mar. 07, 2025
-
5.5
MEDIUMCVE-2023-24752
libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_hevc_epel_pixels_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.... Read more
- Published: Mar. 01, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-24619
Redpanda before 22.3.12 discloses cleartext AWS credentials. The import functionality in the rpk binary logs an AWS Access Key ID and Secret in cleartext to standard output, allowing a local user to view the key in the console, or in Kubernetes logs if st... Read more
Affected Products : redpanda- Published: Feb. 13, 2023
- Modified: Mar. 21, 2025
-
5.5
MEDIUMCVE-2018-19976
In YARA 3.8.1, bytecode in a specially crafted compiled rule is exposed to information about its environment, in libyara/exec.c. This is a consequence of the design of the YARA virtual machine.... Read more
Affected Products : yara- Published: Dec. 17, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-1957
IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by the application based on an incorrect return by the httpServletRequest#authenticate() API when an unprotected URI is accessed. IBM X-Forc... Read more
Affected Products : websphere_application_server- Published: Dec. 10, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-24484
A malicious user can cause log files to be written to a directory that they do not have permission to write to.... Read more
Affected Products : workspace- Published: Feb. 16, 2023
- Modified: Mar. 18, 2025
-
5.5
MEDIUMCVE-2018-18456
The function Object::isName() in Object.h (called from Gfx::opSetFillColorN) in Xpdf 4.00 allows remote attackers to cause a denial of service (stack-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.... Read more
Affected Products : xpdf- Published: Oct. 18, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-24454
Jenkins TestQuality Updater Plugin 1.3 and earlier stores the TestQuality Updater password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.... Read more
Affected Products : testquality_updater- Published: Jan. 26, 2023
- Modified: Apr. 02, 2025
-
5.5
MEDIUMCVE-2018-17154
In FreeBSD before 11.2-STABLE(r338987), 11.2-RELEASE-p4, and 11.1-RELEASE-p15, due to insufficient memory checking in the freebsd4_getfsstat system call, a NULL pointer dereference can occur. Unprivileged authenticated local users may be able to cause a d... Read more
Affected Products : freebsd- Published: Sep. 28, 2018
- Modified: Nov. 21, 2024