Latest CVE Feed
-
5.5
MEDIUMCVE-2021-1126
A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an authenticated, local attacker to view credentials for a configured proxy server. The vulnerability is due to clear-text storage and weak p... Read more
- Published: Jan. 13, 2021
- Modified: Nov. 26, 2024
-
5.5
MEDIUMCVE-2021-1117
Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an attacker through specific configuration and with local unprivileged system access may cause improper input validation, which may lead to denial of... Read more
Affected Products : gpu_display_driver- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-1096
NVIDIA Windows GPU Display Driver for Windows contains a vulnerability in the NVIDIA kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where dereferencing a NULL pointer may lead to a system crash.... Read more
Affected Products : gpu_display_driver- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-1078
NVIDIA Windows GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel driver (nvlddmkm.sys) where a NULL pointer dereference may lead to system crash.... Read more
Affected Products : gpu_display_driver- Published: Apr. 21, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-3044
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability all... Read more
Affected Products : banking_corporate_lending- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-0155
Unchecked return value in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.... Read more
- Published: May. 12, 2022
- Modified: May. 05, 2025
-
5.5
MEDIUMCVE-2020-9988
The issue was addressed with improved deletion. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.0 and iPadOS 14.0. A local user may be able to discover a user’s deleted messages.... Read more
- Published: Dec. 08, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-9969
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0. A local user may be able to view senstive user information.... Read more
- Published: Dec. 08, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-9833
A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.5. A local user may be able to read kernel memory.... Read more
- Published: Jun. 09, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-2161
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized read access to the file system when a malicious configuration file is loaded on to the software by a local user. ... Read more
Affected Products : opc_factory_server- Published: May. 16, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-2169
The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticate... Read more
Affected Products : taxopress- Published: Apr. 19, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-9617
Adobe Premiere Rush versions 1.5.8 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.... Read more
- Published: Jun. 26, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-5804
Incorrect command line processing in Chrome in Google Chrome prior to 73.0.3683.75 allowed a local attacker to perform domain spoofing via a crafted domain name.... Read more
- Published: May. 23, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-5765
An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent.... Read more
- Published: Feb. 19, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-29941
llvm-project commit a0138390 was discovered to contain a segmentation fault via the component matchAndRewriteSortOp<mlir::sparse_tensor::SortOp>(mlir::sparse_tensor::SortOp.... Read more
Affected Products : llvm- Published: May. 05, 2023
- Modified: Jan. 29, 2025
-
5.5
MEDIUMCVE-2023-29942
llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::Type::isa<mlir::LLVM::LLVMVoidType.... Read more
Affected Products : llvm- Published: May. 05, 2023
- Modified: Jan. 29, 2025
-
5.5
MEDIUMCVE-2023-29932
llvm-project commit fdbc55a5 was discovered to contain a segmentation fault via the component mlir::IROperand<mlir::OpOperand.... Read more
Affected Products : llvm- Published: May. 05, 2023
- Modified: Jan. 29, 2025
-
5.5
MEDIUMCVE-2023-29761
An issue found in Sleep v.20230303 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the SharedPreference files.... Read more
Affected Products : sleep- Published: Jun. 09, 2023
- Modified: Jan. 06, 2025
-
5.5
MEDIUMCVE-2023-29819
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a crafted payload.... Read more
Affected Products : secureanywhere- Published: May. 12, 2023
- Modified: Jan. 24, 2025
-
5.5
MEDIUMCVE-2020-8003
A double-free vulnerability in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of service by triggering texture allocation failure, because vrend_renderer_resource_allocated_texture is not an appropriate place for a free... Read more
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024