CVE-2022-38860
- EPSS 0.04%
- Veröffentlicht 15.09.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 07:17:11
Certain The MPlayer Project products are vulnerable to Divide By Zero via function demux_open_avi() of libmpdemux/demux_avi.c which affects mencoder. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
CVE-2022-38861
- EPSS 0.05%
- Veröffentlicht 15.09.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 07:17:11
The MPlayer Project mplayer SVN-r38374-13.0.1 is vulnerable to memory corruption via function free_mp_image() of libmpcodecs/mp_image.c.
CVE-2022-38863
- EPSS 0.04%
- Veröffentlicht 15.09.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 07:17:11
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mp_getbits() of libmpdemux/mpeg_hdr.c which affects mencoder and mplayer. This affects mecoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.
CVE-2022-38864
- EPSS 0.04%
- Veröffentlicht 15.09.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 07:17:11
Certain The MPlayer Project products are vulnerable to Buffer Overflow via the function mp_unescape03() of libmpdemux/mpeg_hdr.c. This affects mencoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.
CVE-2022-38865
- EPSS 0.04%
- Veröffentlicht 15.09.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 07:17:12
Certain The MPlayer Project products are vulnerable to Divide By Zero via the function demux_avi_read_packet of libmpdemux/demux_avi.c. This affects mplyer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
CVE-2022-38866
- EPSS 0.07%
- Veröffentlicht 15.09.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 07:17:12
Certain The MPlayer Project products are vulnerable to Buffer Overflow via read_avi_header() of libmpdemux/aviheader.c . This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
CVE-2018-25047
- EPSS 0.34%
- Veröffentlicht 15.09.2022 00:15:09
- Zuletzt bearbeitet 21.11.2024 04:03:26
In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a ...
CVE-2022-40674
- EPSS 0.91%
- Veröffentlicht 14.09.2022 11:15:54
- Zuletzt bearbeitet 30.05.2025 20:15:30
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
CVE-2022-37797
- EPSS 0.32%
- Veröffentlicht 12.09.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:15:11
In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to c...
CVE-2022-38266
- EPSS 0.26%
- Veröffentlicht 09.09.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:16:08
An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.