- EPSS 44.88%
- Veröffentlicht 01.07.2022 08:15:07
- Zuletzt bearbeitet 21.11.2024 07:00:40
The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption w...
- EPSS 95.76%
- Veröffentlicht 21.06.2022 15:15:09
- Zuletzt bearbeitet 03.11.2025 22:15:58
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022...
CVE-2022-1998
- EPSS 0.33%
- Veröffentlicht 09.06.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:41:55
A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate th...
CVE-2022-32250
- EPSS 2.91%
- Veröffentlicht 02.06.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 07:06:01
net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.
CVE-2022-30115
- EPSS 1.26%
- Veröffentlicht 02.06.2022 14:15:51
- Zuletzt bearbeitet 21.11.2024 07:02:11
Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while no...
CVE-2022-27779
- EPSS 2.73%
- Veröffentlicht 02.06.2022 14:15:44
- Zuletzt bearbeitet 21.11.2024 06:56:10
libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie engine" can bebuilt with or without [Public Suffix List](https://public...
CVE-2022-27780
- EPSS 2.47%
- Veröffentlicht 02.06.2022 14:15:44
- Zuletzt bearbeitet 21.11.2024 06:56:10
The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL like `http://example.com%2F127.0....
CVE-2022-27781
- EPSS 2.75%
- Veröffentlicht 02.06.2022 14:15:44
- Zuletzt bearbeitet 27.05.2026 14:16:38
libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending bus...
CVE-2022-27774
- EPSS 1.76%
- Veröffentlicht 02.06.2022 14:15:43
- Zuletzt bearbeitet 27.05.2026 14:16:37
An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to ...
CVE-2022-27775
- EPSS 3.15%
- Veröffentlicht 02.06.2022 14:15:43
- Zuletzt bearbeitet 27.05.2026 14:16:37
An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.