CVE-2022-1973
- EPSS 0.09%
- Veröffentlicht 05.08.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:41:51
A use-after-free flaw was found in the Linux kernel in log_replay in fs/ntfs3/fslog.c in the NTFS journal. This flaw allows a local attacker to crash the system and leads to a kernel information leak problem.
CVE-2022-36123
- EPSS 0.02%
- Veröffentlicht 29.07.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 07:12:26
The Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV guest OS users to cause a denial of service or gain privileges.
CVE-2022-36879
- EPSS 0.04%
- Veröffentlicht 27.07.2022 04:15:10
- Zuletzt bearbeitet 05.05.2025 16:15:17
An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice.
CVE-2022-1671
- EPSS 0.16%
- Veröffentlicht 26.07.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:41:13
A NULL pointer dereference flaw was found in rxrpc_preparse_s in net/rxrpc/server_key.c in the Linux kernel. This flaw allows a local attacker to crash the system or leak internal kernel information.
CVE-2022-31160
- EPSS 10.94%
- Veröffentlicht 20.07.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 07:04:01
jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed with...
CVE-2022-32205
- EPSS 1.4%
- Veröffentlicht 07.07.2022 13:15:08
- Zuletzt bearbeitet 05.05.2025 17:18:12
A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the...
CVE-2022-32206
- EPSS 2.57%
- Veröffentlicht 07.07.2022 13:15:08
- Zuletzt bearbeitet 05.05.2025 17:18:13
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allo...
CVE-2022-32207
- EPSS 0.17%
- Veröffentlicht 07.07.2022 13:15:08
- Zuletzt bearbeitet 23.04.2025 18:15:53
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen...
CVE-2022-32208
- EPSS 0.3%
- Veröffentlicht 07.07.2022 13:15:08
- Zuletzt bearbeitet 05.05.2025 17:18:13
When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.
CVE-2022-2318
- EPSS 0.08%
- Veröffentlicht 06.07.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:45
There are use-after-free vulnerabilities caused by timer handler in net/rose/rose_timer.c of linux that allow attackers to crash linux kernel without any privileges.