CVE-2022-1671
- EPSS 0.31%
- Veröffentlicht 26.07.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:41:13
A NULL pointer dereference flaw was found in rxrpc_preparse_s in net/rxrpc/server_key.c in the Linux kernel. This flaw allows a local attacker to crash the system or leak internal kernel information.
CVE-2022-2327
- EPSS 0.27%
- Veröffentlicht 22.07.2022 10:15:08
- Zuletzt bearbeitet 02.10.2026 13:56:14
io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when executing IORING_OP. Some operations are missing some types, which can lead to incorrect reference c...
CVE-2022-31160
- EPSS 2.48%
- Veröffentlicht 20.07.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 07:04:01
jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed with...
CVE-2022-2318
- EPSS 0.42%
- Veröffentlicht 06.07.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:45
There are use-after-free vulnerabilities caused by timer handler in net/rose/rose_timer.c of linux that allow attackers to crash linux kernel without any privileges.
CVE-2022-2097
- EPSS 4.43%
- Veröffentlicht 05.07.2022 11:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:18
AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't writte...
CVE-2022-34918
- EPSS 5.5%
- Veröffentlicht 04.07.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 07:10:26
An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacke...
- EPSS 44.88%
- Veröffentlicht 01.07.2022 08:15:07
- Zuletzt bearbeitet 21.11.2024 07:00:40
The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption w...
- EPSS 95.76%
- Veröffentlicht 21.06.2022 15:15:09
- Zuletzt bearbeitet 03.11.2025 22:15:58
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022...
CVE-2022-1998
- EPSS 0.33%
- Veröffentlicht 09.06.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:41:55
A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate th...
CVE-2022-32250
- EPSS 2.91%
- Veröffentlicht 02.06.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 07:06:01
net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.