CVE-2022-22720
- EPSS 33.37%
- Veröffentlicht 14.03.2022 11:15:09
- Zuletzt bearbeitet 21.11.2024 06:47:18
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
CVE-2022-22721
- EPSS 19.47%
- Veröffentlicht 14.03.2022 11:15:09
- Zuletzt bearbeitet 21.11.2024 06:47:19
If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.
CVE-2022-23943
- EPSS 65.91%
- Veröffentlicht 14.03.2022 11:15:09
- Zuletzt bearbeitet 01.05.2025 15:37:55
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.
CVE-2022-21716
- EPSS 1.15%
- Veröffentlicht 03.03.2022 21:15:07
- Zuletzt bearbeitet 25.11.2024 18:12:24
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a bu...
CVE-2022-23308
- EPSS 0.06%
- Veröffentlicht 26.02.2022 05:15:08
- Zuletzt bearbeitet 05.05.2025 17:17:56
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
CVE-2021-4115
- EPSS 0.02%
- Veröffentlicht 21.02.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:36:55
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the fai...
CVE-2022-25313
- EPSS 0.16%
- Veröffentlicht 18.02.2022 05:15:08
- Zuletzt bearbeitet 30.05.2025 20:15:26
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
CVE-2022-25314
- EPSS 0.56%
- Veröffentlicht 18.02.2022 05:15:08
- Zuletzt bearbeitet 05.05.2025 17:18:01
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
CVE-2022-25315
- EPSS 9%
- Veröffentlicht 18.02.2022 05:15:08
- Zuletzt bearbeitet 05.05.2025 17:18:01
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
CVE-2022-25235
- EPSS 11.91%
- Veröffentlicht 16.02.2022 01:15:07
- Zuletzt bearbeitet 05.05.2025 17:18:00
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.