CVE-2022-29244
- EPSS 0.9%
- Published 13.06.2022 14:15:09
- Last modified 23.04.2025 17:15:46
npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9...
CVE-2022-1664
- EPSS 0.38%
- Published 26.05.2022 14:15:08
- Last modified 21.11.2024 06:41:12
Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that i...
CVE-2022-1586
- EPSS 0.36%
- Published 16.05.2022 21:15:07
- Last modified 25.03.2025 19:39:30
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occu...
CVE-2022-1587
- EPSS 0.15%
- Published 16.05.2022 21:15:07
- Last modified 21.11.2024 06:41:01
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.
CVE-2022-1622
- EPSS 0.09%
- Published 11.05.2022 15:15:09
- Last modified 21.11.2024 06:41:06
LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.
CVE-2022-1623
- EPSS 0.08%
- Published 11.05.2022 15:15:09
- Last modified 21.11.2024 06:41:07
LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:624, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.
CVE-2022-29824
- EPSS 0.05%
- Published 03.05.2022 03:15:06
- Last modified 21.11.2024 06:59:45
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte...
CVE-2022-25844
- EPSS 0.47%
- Published 01.05.2022 16:15:08
- Last modified 21.11.2024 06:53:06
The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very h...
- EPSS 0.87%
- Published 13.04.2022 16:15:08
- Last modified 21.11.2024 02:26:33
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untruste...
CVE-2022-1210
- EPSS 0.05%
- Published 03.04.2022 09:15:09
- Last modified 21.11.2024 06:40:15
A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a malicious file leads to a denial of service. The attack can be launched remotely but requires user int...