CVE-2015-1931
- EPSS 0.05%
- Published 29.09.2022 03:15:11
- Last modified 21.11.2024 02:26:25
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows l...
CVE-2021-3975
- EPSS 0.26%
- Published 23.08.2022 20:15:08
- Last modified 21.11.2024 06:23:17
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAl...
CVE-2021-20316
- EPSS 0.44%
- Published 23.08.2022 16:15:09
- Last modified 21.11.2024 05:46:21
A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share.
CVE-2021-23177
- EPSS 0.05%
- Published 23.08.2022 16:15:09
- Last modified 21.11.2024 05:51:19
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extrac...
CVE-2021-31566
- EPSS 0.04%
- Published 23.08.2022 16:15:09
- Last modified 21.11.2024 06:05:55
An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger...
CVE-2021-3695
- EPSS 0.06%
- Published 06.07.2022 16:15:08
- Last modified 21.11.2024 06:22:10
A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue ha...
CVE-2021-3696
- EPSS 0.11%
- Published 06.07.2022 16:15:08
- Last modified 21.11.2024 06:22:10
A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an atta...
- EPSS 0.07%
- Published 06.07.2022 16:15:08
- Last modified 21.11.2024 06:22:10
A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a...
CVE-2022-1227
- EPSS 34.75%
- Published 29.04.2022 16:15:08
- Last modified 21.11.2024 06:40:17
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' co...
CVE-2022-27649
- EPSS 0.63%
- Published 04.04.2022 20:15:10
- Last modified 21.11.2024 06:56:05
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabiliti...