CVE-2022-23468
- EPSS 0.14%
- Veröffentlicht 09.12.2022 18:15:13
- Zuletzt bearbeitet 21.11.2024 06:48:37
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_login_wnd_create() function. There are no known workarounds for this i...
CVE-2022-23477
- EPSS 0.16%
- Veröffentlicht 09.12.2022 18:15:13
- Zuletzt bearbeitet 21.11.2024 06:48:38
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in audin_send_open() function. There are no known workarounds for this issue. ...
CVE-2022-3643
- EPSS 0.16%
- Veröffentlicht 07.12.2022 01:15:11
- Zuletzt bearbeitet 21.11.2024 07:19:56
Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux based network backend by sending certain kinds of packets. It appears to be an (unwritten?) assumption i...
CVE-2022-42328
- EPSS 0.01%
- Veröffentlicht 07.12.2022 01:15:11
- Zuletzt bearbeitet 23.04.2025 15:15:51
Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in ...
CVE-2022-42329
- EPSS 0.02%
- Veröffentlicht 07.12.2022 01:15:11
- Zuletzt bearbeitet 23.04.2025 15:15:51
Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in ...
CVE-2022-41325
- EPSS 0.07%
- Veröffentlicht 06.12.2022 16:15:11
- Zuletzt bearbeitet 23.04.2025 20:15:41
An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.
CVE-2022-24439
- EPSS 70.54%
- Veröffentlicht 06.12.2022 05:15:11
- Zuletzt bearbeitet 21.11.2024 06:50:25
All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possibl...
CVE-2022-30122
- EPSS 0.92%
- Veröffentlicht 05.12.2022 22:15:10
- Zuletzt bearbeitet 21.11.2024 07:02:12
A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack.
- EPSS 2.26%
- Veröffentlicht 05.12.2022 22:15:10
- Zuletzt bearbeitet 21.11.2024 07:02:12
A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.
CVE-2022-32221
- EPSS 1.2%
- Veröffentlicht 05.12.2022 22:15:10
- Zuletzt bearbeitet 21.11.2024 07:05:57
When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request wh...