CVE-2022-1632
- EPSS 0.16%
- Published 01.09.2022 21:15:08
- Last modified 21.11.2024 06:41:08
An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an i...
CVE-2022-2132
- EPSS 0.69%
- Published 31.08.2022 16:15:10
- Last modified 21.11.2024 07:00:23
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
CVE-2022-0669
- EPSS 0.13%
- Published 29.08.2022 15:15:09
- Last modified 21.11.2024 06:39:08
A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sendi...
CVE-2022-0718
- EPSS 0.33%
- Published 29.08.2022 15:15:09
- Last modified 21.11.2024 06:39:15
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
CVE-2021-3669
- EPSS 0.01%
- Published 26.08.2022 16:15:09
- Last modified 21.11.2024 06:22:06
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
CVE-2021-3827
- EPSS 0.22%
- Published 23.08.2022 16:15:10
- Last modified 21.11.2024 06:22:33
A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an attacker can bypass the MFA authentication by sending a SOAP request with an AuthnRequest and Authoriza...
CVE-2020-27836
- EPSS 0.72%
- Published 22.08.2022 15:15:12
- Last modified 21.11.2024 05:21:54
A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat fr...
CVE-2021-3695
- EPSS 0.06%
- Published 06.07.2022 16:15:08
- Last modified 21.11.2024 06:22:10
A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue ha...
CVE-2021-3696
- EPSS 0.11%
- Published 06.07.2022 16:15:08
- Last modified 21.11.2024 06:22:10
A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an atta...
- EPSS 0.07%
- Published 06.07.2022 16:15:08
- Last modified 21.11.2024 06:22:10
A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a...