CVE-2022-27219
- EPSS 0.18%
- Published 14.06.2022 10:15:19
- Last modified 21.11.2024 06:55:26
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 443. This could aid attackers by making the servers more...
CVE-2022-25315
- EPSS 9%
- Published 18.02.2022 05:15:08
- Last modified 05.05.2025 17:18:01
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
CVE-2022-25314
- EPSS 0.56%
- Published 18.02.2022 05:15:08
- Last modified 05.05.2025 17:18:01
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
CVE-2022-25313
- EPSS 0.16%
- Published 18.02.2022 05:15:08
- Last modified 30.05.2025 20:15:26
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
CVE-2022-25236
- EPSS 10.89%
- Published 16.02.2022 01:15:07
- Last modified 05.05.2025 17:18:01
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
CVE-2022-25235
- EPSS 11.91%
- Published 16.02.2022 01:15:07
- Last modified 05.05.2025 17:18:00
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
CVE-2022-23102
- EPSS 4.85%
- Published 09.02.2022 16:15:15
- Last modified 21.11.2024 06:47:59
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into clicking a malicious link there...
CVE-2022-23990
- EPSS 4.36%
- Published 26.01.2022 19:15:08
- Last modified 05.05.2025 17:17:59
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
CVE-2022-23852
- EPSS 1.71%
- Published 24.01.2022 02:15:06
- Last modified 05.05.2025 17:17:58
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
CVE-2022-22827
- EPSS 0.25%
- Published 10.01.2022 14:12:57
- Last modified 05.05.2025 17:17:53
storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.