CVE-2022-27781
- EPSS 0.05%
- Published 02.06.2022 14:15:44
- Last modified 21.11.2024 06:56:10
libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending bus...
CVE-2022-27779
- EPSS 0.19%
- Published 02.06.2022 14:15:44
- Last modified 21.11.2024 06:56:10
libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie engine" can bebuilt with or without [Public Suffix List](https://public...
CVE-2022-30594
- EPSS 0.03%
- Published 12.05.2022 05:15:06
- Last modified 21.11.2024 07:02:59
The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.
- EPSS 24.91%
- Published 19.04.2022 21:15:16
- Last modified 21.11.2024 06:44:43
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.2 and 18; Oracle GraalVM Enterprise Edition: 21.3.1 and 22.0.0.2. E...
CVE-2018-25032
- EPSS 0.09%
- Published 25.03.2022 09:15:08
- Last modified 21.08.2025 20:37:11
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
CVE-2022-0492
- EPSS 6.99%
- Published 03.03.2022 19:15:08
- Last modified 21.11.2024 06:38:46
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the...
CVE-2021-3772
- EPSS 0.16%
- Published 02.03.2022 23:15:09
- Last modified 21.11.2024 06:22:23
A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP ad...
CVE-2022-0391
- EPSS 0.95%
- Published 09.02.2022 23:15:16
- Last modified 21.11.2024 06:38:31
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r...
CVE-2021-2161
- EPSS 0.27%
- Published 22.04.2021 22:15:13
- Last modified 21.11.2024 06:02:30
Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE Embedded: 8u281; Oracle GraalVM E...
CVE-2021-2163
- EPSS 0.12%
- Published 22.04.2021 22:15:13
- Last modified 21.11.2024 06:02:30
Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE Embedded: 8u281; Oracle GraalVM E...