Latest CVE Feed
-
5.5
MEDIUMCVE-2023-21260
In notification access permission dialog box, malicious application can embedded a very long service label that overflow the original user prompt and possibly contains mis-leading information to be appeared as a system message for user confirmation. ... Read more
Affected Products : android- Published: Jul. 13, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-21268
In update of MmsProvider.java, there is a possible way to change directory permissions due to a path traversal error. This could lead to local denial of service of SIM recognition with no additional execution privileges needed. User interaction is not nee... Read more
Affected Products : android- Published: Aug. 14, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-21252
In validatePassword of WifiConfigurationUtil.java, there is a possible way to get the device into a boot loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is ... Read more
Affected Products : android- Published: Oct. 06, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-28191
This issue was addressed with improved redaction of sensitive information. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to bypass Privacy prefe... Read more
- Published: Jun. 23, 2023
- Modified: Dec. 05, 2024
-
5.5
MEDIUMCVE-2018-1000667
NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handling a crafted file due to function assemble_file(inname, depend_ptr) at asm/nasm.c:482. vulnerability in function assemble_file(inname, ... Read more
- Published: Sep. 06, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-21238
In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. ... Read more
Affected Products : android- Published: Jul. 13, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-21292
In openContentUri of ActivityManagerService.java, there is a possible way for a third party app to obtain restricted files due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User inter... Read more
Affected Products : android- Published: Aug. 14, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-21230
In onAccessPointChanged of AccessPointPreference.java, there is a possible way for unprivileged apps to receive a broadcast about WiFi access point change and its BSSID or SSID due to a precondition check failure. This could lead to local information disc... Read more
Affected Products : android- Published: Aug. 14, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2000-1178
Joe text editor follows symbolic links when creating a rescue copy called DEADJOE during an abnormal exit, which allows local users to overwrite the files of other users whose joe session crashes.... Read more
- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2023-21211
In multiple files, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersio... Read more
Affected Products : android- Published: Jun. 28, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-21205
In startWpsPinDisplayInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi... Read more
Affected Products : android- Published: Jun. 28, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-1000524
miniSphere version 5.2.9 and earlier contains a Integer Overflow vulnerability in layer_resize() function in map_engine.c that can result in remote denial of service. This attack appear to be exploitable via the victim must load a specially-crafted map wh... Read more
Affected Products : minisphere- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-21177
In requestAppKeyboardShortcuts of WindowManagerService.java, there is a possible way to infer the app a user is interacting with due to a missing permission check. This could lead to local information disclosure with no additional execution privileges nee... Read more
Affected Products : android- Published: Jun. 28, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2023-21173
In multiple methods of DataUsageList.java, there is a possible way to learn about admin user's network activities due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User inter... Read more
Affected Products : android- Published: Jun. 28, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1282
IBM Content Navigator & CMIS 2.0 and 3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within ... Read more
Affected Products : content_navigator- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2023-48114
SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored XSS by using image/svg+xml and an uploaded SVG document. This occurs because the application tries to allow youtube.com URLs, but actually allows youtube.com followed by an @ character a... Read more
Affected Products : smartermail- Published: Dec. 21, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-44075
Cross Site Scripting vulnerability in Small CRM in PHP v.3.0 allows a remote attacker to execute arbitrary code via a crafted payload to the Address parameter.... Read more
Affected Products : small_crm- Published: Oct. 04, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1114
IBM Campaign 9.1, 9.1.2, and 10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted... Read more
Affected Products : campaign- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-20043
A vulnerability was found in Navetti PricePoint 4.6.0.0 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting (Persistent). The attack may be launched remotely. Upgrading ... Read more
Affected Products : pricepoint- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1306
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering... Read more
- Published: Jul. 03, 2018
- Modified: Nov. 21, 2024