CVE-2022-25236
- EPSS 10.89%
- Veröffentlicht 16.02.2022 01:15:07
- Zuletzt bearbeitet 05.05.2025 17:18:01
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
CVE-2022-0391
- EPSS 0.95%
- Veröffentlicht 09.02.2022 23:15:16
- Zuletzt bearbeitet 21.11.2024 06:38:31
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r...
CVE-2021-4034
- EPSS 86.52%
- Veröffentlicht 28.01.2022 20:15:12
- Zuletzt bearbeitet 03.04.2025 18:53:12
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pk...
CVE-2022-21375
- EPSS 0.06%
- Veröffentlicht 19.01.2022 12:15:16
- Zuletzt bearbeitet 21.11.2024 06:44:33
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris exe...
- EPSS 0.45%
- Veröffentlicht 19.01.2022 12:15:11
- Zuletzt bearbeitet 21.11.2024 06:44:15
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13; Oracle GraalVM Enterprise Edition: 20.3.4 and 21....
CVE-2021-4181
- EPSS 0.06%
- Veröffentlicht 30.12.2021 22:15:10
- Zuletzt bearbeitet 21.11.2024 06:37:05
Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
CVE-2021-4182
- EPSS 0.05%
- Veröffentlicht 30.12.2021 22:15:10
- Zuletzt bearbeitet 21.11.2024 06:37:05
Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
CVE-2021-4183
- EPSS 0.05%
- Veröffentlicht 30.12.2021 22:15:10
- Zuletzt bearbeitet 21.11.2024 06:37:05
Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
CVE-2021-4184
- EPSS 0.06%
- Veröffentlicht 30.12.2021 22:15:10
- Zuletzt bearbeitet 21.11.2024 06:37:05
Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
CVE-2021-4185
- EPSS 0.07%
- Veröffentlicht 30.12.2021 22:15:10
- Zuletzt bearbeitet 21.11.2024 06:37:05
Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file