Vulnerabilities (CVE)

Filtered by CWE-20
Total 10572 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-5050 1 Konversation 1 Konversation 2024-11-21 5.0 MEDIUM 7.5 HIGH
konversation before 1.2.3 allows attackers to cause a denial of service.
CVE-2009-5004 1 Apache 1 Qpid-cpp 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .
CVE-2009-3614 2 Debian, Noping 2 Debian Linux, Liboping 2024-11-21 2.1 LOW 3.3 LOW
liboping 1.3.2 allows users reading arbitrary files upon the local system.
CVE-2007-6763 1 Sas 1 Sas Drug Development 2024-11-21 6.5 MEDIUM 8.8 HIGH
SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources by pressing a back or forward button in a web browser.
CVE-2005-4890 3 Debian, Redhat, Sudo Project 4 Debian Linux, Shadow, Enterprise Linux and 1 more 2024-11-21 7.2 HIGH 7.8 HIGH
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.
CVE-2002-2444 1 Snoopy Project 1 Snoopy 2024-11-20 7.5 HIGH 9.8 CRITICAL
Snoopy before 2.0.0 has a security hole in exec cURL
CVE-2024-41167 1 Intel 2 M10jnp2sb, M10jnp2sb Firmware 2024-11-19 N/A 6.7 MEDIUM
Improper input validation in UEFI firmware in some Intel(R) Server Board M10JNP2SB Family may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2021-34752 2024-11-18 N/A 6.7 MEDIUM
A vulnerability in the CLI of Cisco FTD Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands with root privileges on the underlying operating system of an affected device.  This vulnerability is due to insufficient validation of user-supplied command arguments. An attacker could exploit this vulnerability by submitting crafted input to the affected commands. A successful exploit could allow the attacker to execute commands with root privileges on the underlying operating system. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
CVE-2024-0793 2024-11-18 N/A 7.7 HIGH
A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial of service due to KCM pods going into restart churn.
CVE-2024-49033 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2024-11-16 N/A 7.5 HIGH
Microsoft Word Security Feature Bypass Vulnerability
CVE-2024-21949 1 Amd 1 Ryzen Ai Software 2024-11-15 N/A 5.5 MEDIUM
Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system crash.
CVE-2024-21974 1 Amd 1 Ryzen Ai Software 2024-11-15 N/A 7.8 HIGH
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.
CVE-2024-21975 1 Amd 1 Ryzen Ai Software 2024-11-15 N/A 7.8 HIGH
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.
CVE-2024-36284 2024-11-15 N/A 5.5 MEDIUM
Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
CVE-2024-31158 2024-11-15 N/A 7.5 HIGH
Improper input validation in UEFI firmware in some Intel(R) Server Board S2600BP Family may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2024-33624 2024-11-15 N/A 4.3 MEDIUM
Improper input validation for some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.60 may allow an unauthenticated user to potentially enable denial of service via network access.
CVE-2024-32048 2024-11-15 N/A 6.5 MEDIUM
Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Model Server software before version 2024.0 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
CVE-2024-32485 2024-11-15 N/A 3.9 LOW
Improper Input Validation in some Intel(R) VROC software before version 8.6.0.2003 may allow an authenticated user to potentially enable denial of service via local access.
CVE-2024-39811 2024-11-15 N/A 6.3 MEDIUM
Improper input validation in firmware for some Intel(R) Server M20NTP Family UEFI may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2024-28028 2024-11-15 N/A 7.5 HIGH
Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.