CVE-2022-26966
- EPSS 0.03%
- Veröffentlicht 12.03.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:54:52
An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitive information from heap memory via crafted frame lengths from a device.
CVE-2020-36518
- EPSS 0.51%
- Veröffentlicht 11.03.2022 07:15:07
- Zuletzt bearbeitet 27.08.2025 21:15:36
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
- EPSS 1.82%
- Veröffentlicht 10.03.2022 17:47:45
- Zuletzt bearbeitet 21.11.2024 06:54:02
In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may allow a local attacker to add user-writable directories to the system search path. To exploit, an administrator mus...
CVE-2022-0891
- EPSS 0.05%
- Veröffentlicht 10.03.2022 17:44:58
- Zuletzt bearbeitet 21.11.2024 06:39:36
A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential in...
CVE-2022-0865
- EPSS 0.07%
- Veröffentlicht 10.03.2022 17:44:57
- Zuletzt bearbeitet 21.11.2024 06:39:33
Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045.
CVE-2022-26336
- EPSS 0.05%
- Veröffentlicht 04.03.2022 16:15:10
- Zuletzt bearbeitet 21.11.2024 06:53:46
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad ...
CVE-2022-23308
- EPSS 0.06%
- Veröffentlicht 26.02.2022 05:15:08
- Zuletzt bearbeitet 05.05.2025 17:17:56
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
CVE-2022-24407
- EPSS 0.64%
- Veröffentlicht 24.02.2022 15:15:29
- Zuletzt bearbeitet 21.11.2024 06:50:21
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
CVE-2021-20322
- EPSS 0.13%
- Veröffentlicht 18.02.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 05:46:22
A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass ...
CVE-2022-25258
- EPSS 0.33%
- Veröffentlicht 16.02.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:53
An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function ...