CVE-2020-10650
- EPSS 6.19%
- Veröffentlicht 26.12.2022 20:15:10
- Zuletzt bearbeitet 19.08.2025 16:37:03
A deserialization flaw was discovered in jackson-databind through 2.9.10.4. It could allow an unauthenticated user to perform code execution via ignite-jta or quartz-core: org.apache.ignite.cache.jta.jndi.CacheJndiTmLookup, org.apache.ignite.cache.jt...
CVE-2022-43551
- EPSS 0.03%
- Veröffentlicht 23.12.2022 15:15:15
- Zuletzt bearbeitet 21.11.2024 07:26:45
A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the U...
CVE-2022-40304
- EPSS 0.11%
- Veröffentlicht 23.11.2022 18:15:12
- Zuletzt bearbeitet 28.04.2025 20:15:19
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
CVE-2022-40303
- EPSS 0.26%
- Veröffentlicht 23.11.2022 00:15:11
- Zuletzt bearbeitet 29.04.2025 05:15:43
An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset,...
CVE-2022-3970
- EPSS 0.08%
- Veröffentlicht 13.11.2022 08:15:16
- Zuletzt bearbeitet 21.11.2024 07:20:38
A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. Th...
CVE-2022-45061
- EPSS 0.08%
- Veröffentlicht 09.11.2022 07:15:09
- Zuletzt bearbeitet 01.05.2025 15:15:58
An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead t...
CVE-2022-43945
- EPSS 0.94%
- Veröffentlicht 04.11.2022 19:15:11
- Zuletzt bearbeitet 01.05.2025 19:15:55
The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks the number of pages held by each NFSD thread by combining the receive and send buffers of a remote procedure call (RPC) into a sin...
CVE-2022-31690
- EPSS 0.21%
- Veröffentlicht 31.10.2022 20:15:12
- Zuletzt bearbeitet 08.05.2025 19:15:52
Spring Security, versions 5.7 prior to 5.7.5, and 5.6 prior to 5.6.9, and older unsupported versions could be susceptible to a privilege escalation under certain conditions. A malicious user or attacker can modify a request initiated by the Client (v...
CVE-2022-31692
- EPSS 7.64%
- Veröffentlicht 31.10.2022 20:15:12
- Zuletzt bearbeitet 06.05.2025 16:15:23
Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: The applica...
CVE-2022-3705
- EPSS 0.3%
- Veröffentlicht 26.10.2022 20:15:10
- Zuletzt bearbeitet 21.11.2024 07:20:04
A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component autocmd Handler. The manipulation leads to use after free. The attack may be launched remo...