CVE-2022-25313
- EPSS 0.16%
- Published 18.02.2022 05:15:08
- Last modified 30.05.2025 20:15:26
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
CVE-2022-25314
- EPSS 0.56%
- Published 18.02.2022 05:15:08
- Last modified 05.05.2025 17:18:01
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
CVE-2022-25315
- EPSS 9%
- Published 18.02.2022 05:15:08
- Last modified 05.05.2025 17:18:01
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
CVE-2022-25235
- EPSS 11.91%
- Published 16.02.2022 01:15:07
- Last modified 05.05.2025 17:18:00
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
CVE-2022-25236
- EPSS 10.89%
- Published 16.02.2022 01:15:07
- Last modified 05.05.2025 17:18:01
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
CVE-2022-0391
- EPSS 0.95%
- Published 09.02.2022 23:15:16
- Last modified 21.11.2024 06:38:31
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r...
CVE-2021-4034
- EPSS 86.52%
- Published 28.01.2022 20:15:12
- Last modified 03.04.2025 18:53:12
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pk...
CVE-2022-21375
- EPSS 0.06%
- Published 19.01.2022 12:15:16
- Last modified 21.11.2024 06:44:33
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris exe...
- EPSS 0.45%
- Published 19.01.2022 12:15:11
- Last modified 21.11.2024 06:44:15
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13; Oracle GraalVM Enterprise Edition: 20.3.4 and 21....
CVE-2021-4181
- EPSS 0.06%
- Published 30.12.2021 22:15:10
- Last modified 21.11.2024 06:37:05
Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file