CVE-2022-21716
- EPSS 1.15%
- Veröffentlicht 03.03.2022 21:15:07
- Zuletzt bearbeitet 25.11.2024 18:12:24
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a bu...
CVE-2022-0492
- EPSS 5.8%
- Veröffentlicht 03.03.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:38:46
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the...
CVE-2022-23648
- EPSS 6.3%
- Veröffentlicht 03.03.2022 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:49:00
containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-craf...
CVE-2021-3772
- EPSS 0.16%
- Veröffentlicht 02.03.2022 23:15:09
- Zuletzt bearbeitet 21.11.2024 06:22:23
A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP ad...
CVE-2021-3667
- EPSS 0.28%
- Veröffentlicht 02.03.2022 23:15:08
- Zuletzt bearbeitet 10.02.2025 13:10:12
An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients co...
CVE-2022-0711
- EPSS 66.48%
- Veröffentlicht 02.03.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:39:14
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service cond...
CVE-2022-0577
- EPSS 0.17%
- Veröffentlicht 02.03.2022 04:15:06
- Zuletzt bearbeitet 21.11.2024 06:38:57
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.
- EPSS 0.84%
- Veröffentlicht 01.03.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:50:56
image_processing is an image processing wrapper for libvips and ImageMagick/GraphicsMagick. Prior to version 1.12.2, using the `#apply` method from image_processing to apply a series of operations that are coming from unsanitized user input allows th...
CVE-2022-23308
- EPSS 0.06%
- Veröffentlicht 26.02.2022 05:15:08
- Zuletzt bearbeitet 05.05.2025 17:17:56
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
CVE-2022-21824
- EPSS 0.4%
- Veröffentlicht 24.02.2022 19:15:10
- Zuletzt bearbeitet 21.11.2024 06:45:30
Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, whi...