Latest CVE Feed
-
5.5
MEDIUMCVE-2023-21577
Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitatio... Read more
- Published: Feb. 17, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-10212
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization leading to creation of folders within another account via a modified device value.... Read more
Affected Products : enterprise_file_sharing- Published: Apr. 25, 2018
- Modified: May. 30, 2025
-
5.5
MEDIUMCVE-2023-21578
Photoshop version 23.5.3 (and earlier), 24.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitatio... Read more
- Published: Feb. 17, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-10196
NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows remote attackers to cause a denial of service (application crash) via a crafted file.... Read more
- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-21550
Windows Cryptographic Information Disclosure Vulnerability... Read more
- Published: Jan. 10, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-10187
In radare2 2.5.0, there is a heap-based buffer over-read in the dalvik_op function (libr/anal/p/anal_dalvik.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. Note that this issue is different from ... Read more
Affected Products : radare2- Published: Apr. 17, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-10186
In radare2 2.5.0, there is a heap-based buffer over-read in the r_hex_bin2str function (libr/util/hex.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. This issue is different from CVE-2017-15368.... Read more
Affected Products : radare2- Published: Apr. 17, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-3679
A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN capability) could use this flaw to st... Read more
- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-21559
Windows Cryptographic Information Disclosure Vulnerability... Read more
- Published: Jan. 10, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-3602
An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in ... Read more
- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2000-0338
Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creating the lock directory before it is created for use by a legitimate CVS user.... Read more
Affected Products : concurrent_versions_software- Published: Apr. 23, 2000
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2023-21511
Out-of-bounds Read vulnerability while processing CMD_COLDWALLET_BTC_SET_PRV_UTXO in bc_core trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.... Read more
- Published: May. 04, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-21507
Out-of-bounds Read vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.... Read more
- Published: May. 04, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-10124
The kill_something_info function in kernel/signal.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service via an INT_MIN argument.... Read more
- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-3429
When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.... Read more
Affected Products : cloud-init- Published: Apr. 19, 2023
- Modified: Feb. 05, 2025
-
5.5
MEDIUMCVE-2023-21437
Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit broadcast.... Read more
- Published: Feb. 09, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-21423
Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission using unprotected action.... Read more
- Published: Feb. 09, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-10087
The kernel_wait4 function in kernel/exit.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service by triggering an attempted use of the -INT_MIN value.... Read more
- Published: Apr. 13, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-10074
The hi3660_stub_clk_probe function in drivers/clk/hisilicon/clk-hi3660-stub.c in the Linux kernel before 4.16 allows local users to cause a denial of service (NULL pointer dereference) by triggering a failure of resource retrieval.... Read more
Affected Products : linux_kernel- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-21394
In registerPhoneAccount of TelecomServiceImpl.java, there is a possible way to reveal images from another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interact... Read more
Affected Products : android- Published: Oct. 30, 2023
- Modified: Nov. 21, 2024