- EPSS 0.01%
- Published 18.05.2022 17:15:08
- Last modified 21.11.2024 06:41:21
A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine.
CVE-2022-1116
- EPSS 0.04%
- Published 17.05.2022 17:15:08
- Last modified 21.11.2024 06:40:04
Integer Overflow or Wraparound vulnerability in io_uring of Linux Kernel allows local attacker to cause memory corruption and escalate privileges to root. This issue affects: Linux Kernel versions prior to 5.4.189; version 5.4.24 and later versions.
CVE-2022-29581
- EPSS 0.25%
- Published 17.05.2022 17:15:08
- Last modified 21.11.2024 06:59:20
Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions.
CVE-2022-1586
- EPSS 0.36%
- Published 16.05.2022 21:15:07
- Last modified 25.03.2025 19:39:30
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occu...
CVE-2022-1587
- EPSS 0.15%
- Published 16.05.2022 21:15:07
- Last modified 21.11.2024 06:41:01
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.
CVE-2022-1679
- EPSS 0.09%
- Published 16.05.2022 18:15:08
- Last modified 21.11.2024 06:41:14
A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate the...
CVE-2022-30594
- EPSS 0.03%
- Published 12.05.2022 05:15:06
- Last modified 21.11.2024 07:02:59
The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.
CVE-2022-29155
- EPSS 20.93%
- Published 04.05.2022 20:15:07
- Last modified 21.11.2024 06:58:36
In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter ...
- EPSS 46.34%
- Published 03.05.2022 16:15:18
- Last modified 13.08.2025 14:15:28
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execut...
CVE-2022-1343
- EPSS 0.13%
- Published 03.05.2022 16:15:18
- Last modified 05.05.2025 17:17:34
The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the res...