CVE-2022-43680
- EPSS 2.32%
- Veröffentlicht 24.10.2022 14:15:53
- Zuletzt bearbeitet 30.05.2025 20:15:31
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
- EPSS 0.79%
- Veröffentlicht 21.10.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 07:19:57
A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_new_inode of the file fs/nilfs2/inode.c of the component BPF. The manipulation leads to use after free. It is possible to launch the atta...
CVE-2022-3564
- EPSS 1.33%
- Veröffentlicht 17.10.2022 19:15:10
- Zuletzt bearbeitet 21.11.2024 07:19:46
A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is r...
CVE-2022-3545
- EPSS 0.42%
- Veröffentlicht 17.10.2022 12:15:11
- Zuletzt bearbeitet 21.11.2024 07:19:44
A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerability is the function area_cache_get of the file drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c of the component IPsec. The manipulation lea...
CVE-2022-35252
- EPSS 1.91%
- Veröffentlicht 23.09.2022 14:15:12
- Zuletzt bearbeitet 05.05.2025 17:18:16
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service...
CVE-2022-3202
- EPSS 0.25%
- Veröffentlicht 14.09.2022 15:15:11
- Zuletzt bearbeitet 21.11.2024 07:19:02
A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This could allow a local attacker to crash the system or leak kernel internal information.
CVE-2022-2526
- EPSS 1.11%
- Veröffentlicht 09.09.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 07:01:11
A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other...
CVE-2022-2964
- EPSS 0.3%
- Veröffentlicht 09.09.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 07:01:59
A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes.
CVE-2022-39046
- EPSS 1.6%
- Veröffentlicht 31.08.2022 06:15:07
- Zuletzt bearbeitet 21.11.2024 07:17:26
An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a por...
CVE-2022-1199
- EPSS 1.58%
- Veröffentlicht 29.08.2022 15:15:10
- Zuletzt bearbeitet 11.09.2026 16:18:07
A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-after-free vulnerability.