CVE-2022-32813
- EPSS 0.12%
- Veröffentlicht 24.08.2022 20:15:08
- Zuletzt bearbeitet 29.05.2025 18:15:21
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. An app with root privileges may be able to e...
CVE-2022-32834
- EPSS 0.07%
- Veröffentlicht 24.08.2022 20:15:08
- Zuletzt bearbeitet 29.05.2025 18:15:22
An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina. An app may be able to access sensitive user information.
CVE-2022-32837
- EPSS 0.07%
- Veröffentlicht 24.08.2022 20:15:08
- Zuletzt bearbeitet 29.05.2025 18:15:22
This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5, tvOS 15.6, iOS 15.6 and iPadOS 15.6. An app may be able to cause unexpected system termination or write kernel memory.
CVE-2022-32838
- EPSS 0.07%
- Veröffentlicht 24.08.2022 20:15:08
- Zuletzt bearbeitet 29.05.2025 18:15:22
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6. An app may be able to read arbitrary files.
CVE-2022-37434
- EPSS 92.54%
- Veröffentlicht 05.08.2022 07:15:07
- Zuletzt bearbeitet 30.05.2025 20:15:30
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib s...
CVE-2022-2294
- EPSS 1.17%
- Veröffentlicht 28.07.2022 02:15:07
- Zuletzt bearbeitet 24.10.2025 14:09:38
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2022-32205
- EPSS 2.59%
- Veröffentlicht 07.07.2022 13:15:08
- Zuletzt bearbeitet 05.05.2025 17:18:12
A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the...
CVE-2022-32207
- EPSS 0.2%
- Veröffentlicht 07.07.2022 13:15:08
- Zuletzt bearbeitet 23.04.2025 18:15:53
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen...
CVE-2022-32208
- EPSS 0.31%
- Veröffentlicht 07.07.2022 13:15:08
- Zuletzt bearbeitet 05.05.2025 17:18:13
When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.
CVE-2022-1720
- EPSS 0.52%
- Veröffentlicht 20.06.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:41:19
Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.