CVE-2025-24014
- EPSS 0.05%
- Published 20.01.2025 23:15:07
- Last modified 14.08.2025 01:40:54
Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a screen and just operates silently in batch mode. However, it is still possible to trigger ...
CVE-2022-43680
- EPSS 0.31%
- Published 24.10.2022 14:15:53
- Last modified 30.05.2025 20:15:31
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
CVE-2022-27778
- EPSS 0.46%
- Published 02.06.2022 14:15:43
- Last modified 21.11.2024 06:56:10
A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.
- EPSS 0.11%
- Published 19.04.2022 21:15:15
- Last modified 21.11.2024 06:44:41
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20...
- EPSS 0.06%
- Published 19.04.2022 21:15:15
- Last modified 21.11.2024 06:44:40
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5,...
CVE-2022-28893
- EPSS 0.03%
- Published 11.04.2022 05:15:07
- Last modified 21.11.2024 06:58:09
The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state.
- EPSS 0.1%
- Published 08.04.2022 05:15:07
- Last modified 21.11.2024 06:57:57
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
CVE-2021-3733
- EPSS 0.68%
- Published 10.03.2022 17:42:59
- Last modified 21.11.2024 06:22:16
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication r...
CVE-2021-20322
- EPSS 0.12%
- Published 18.02.2022 18:15:09
- Last modified 21.11.2024 05:46:22
A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass ...
CVE-2021-45485
- EPSS 0.52%
- Published 25.12.2021 02:15:06
- Last modified 21.11.2024 06:32:18
In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among ma...