CVE-2022-21716
- EPSS 0.97%
- Veröffentlicht 03.03.2022 21:15:07
- Zuletzt bearbeitet 25.11.2024 18:12:24
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a bu...
CVE-2022-25313
- EPSS 0.13%
- Veröffentlicht 18.02.2022 05:15:08
- Zuletzt bearbeitet 30.05.2025 20:15:26
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
CVE-2022-25314
- EPSS 0.37%
- Veröffentlicht 18.02.2022 05:15:08
- Zuletzt bearbeitet 05.05.2025 17:18:01
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
CVE-2022-25315
- EPSS 7.7%
- Veröffentlicht 18.02.2022 05:15:08
- Zuletzt bearbeitet 05.05.2025 17:18:01
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
CVE-2022-25235
- EPSS 13.32%
- Veröffentlicht 16.02.2022 01:15:07
- Zuletzt bearbeitet 05.05.2025 17:18:00
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
CVE-2022-25236
- EPSS 9.36%
- Veröffentlicht 16.02.2022 01:15:07
- Zuletzt bearbeitet 05.05.2025 17:18:01
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
CVE-2022-0391
- EPSS 1.92%
- Veröffentlicht 09.02.2022 23:15:16
- Zuletzt bearbeitet 17.12.2025 21:15:52
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r...
CVE-2021-4034
- EPSS 87.26%
- Veröffentlicht 28.01.2022 20:15:12
- Zuletzt bearbeitet 06.11.2025 14:50:26
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pk...
CVE-2022-21375
- EPSS 0.06%
- Veröffentlicht 19.01.2022 12:15:16
- Zuletzt bearbeitet 21.11.2024 06:44:33
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris exe...
- EPSS 0.5%
- Veröffentlicht 19.01.2022 12:15:11
- Zuletzt bearbeitet 21.11.2024 06:44:15
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13; Oracle GraalVM Enterprise Edition: 20.3.4 and 21....