Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-12-19 CVE-2021-20553 IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting.
network
low complexity
CWE-79
5.4
2024-12-19 CVE-2021-29827 IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim.
low complexity
CWE-1021
5.2
2024-12-19 CVE-2022-44515 Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure.
local
low complexity
CWE-125
5.5
2024-12-19 CVE-2022-44516 Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure.
local
low complexity
CWE-125
5.5
2024-12-19 CVE-2022-44517 Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure.
local
low complexity
CWE-125
5.5
2024-12-19 CVE-2022-44519 Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could lead to disclosure of sensitive memory.
local
low complexity
CWE-416
5.5
2024-12-19 CVE-2023-21586 Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a NULL Pointer Dereference vulnerability.
local
low complexity
CWE-476
5.5
2024-12-18 CVE-2022-40732 An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643.
local
low complexity
CWE-476
5.0
2024-12-18 CVE-2022-40733 An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643.
local
low complexity
CWE-476
5.0
2024-12-18 CVE-2024-51470 IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM MQ for HPE NonStop 8.1.0 through 8.1.0.25 could allow an authenticated user to cause a denial-of-service due to messages with improperly set values.
network
low complexity
CWE-754
6.5