CVE-2021-3759
- EPSS 0.02%
- Published 23.08.2022 16:15:09
- Last modified 21.11.2024 06:22:21
A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing ...
CVE-2021-3800
- EPSS 0.06%
- Published 23.08.2022 16:15:09
- Last modified 21.11.2024 06:22:28
A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by privileged users to unprivileged ones under the right condition.
CVE-2022-2873
- EPSS 0.03%
- Published 22.08.2022 15:15:15
- Last modified 21.11.2024 07:01:51
An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a user triggers the I2C_SMBUS_BLOCK_DATA (with the ioctl I2C_SMBUS) with malicious input data. This flaw allows a local user to cra...
CVE-2020-27792
- EPSS 0.05%
- Published 19.08.2022 23:15:08
- Last modified 30.04.2025 10:15:15
A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could l...
CVE-2022-26373
- EPSS 0.3%
- Published 18.08.2022 20:15:11
- Last modified 05.05.2025 17:18:03
Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
CVE-2021-32862
- EPSS 0.57%
- Published 18.08.2022 19:15:14
- Last modified 21.11.2024 06:07:54
The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to ...
CVE-2022-2867
- EPSS 0.03%
- Published 17.08.2022 22:15:08
- Last modified 21.11.2024 07:01:50
libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who supplies a crafted file to tiffcrop (likely via tricking a user to run tiffcrop on it with certain parameters) could cause a crash or i...
CVE-2022-2868
- EPSS 0.02%
- Published 17.08.2022 22:15:08
- Last modified 21.11.2024 07:01:50
libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is able to supply a crafted file to tiffcrop.
CVE-2022-2869
- EPSS 0.03%
- Published 17.08.2022 22:15:08
- Last modified 21.11.2024 07:01:50
libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples8bits routine. An attacker who supplies a crafted file to tiffcrop could trigger this flaw, most likely by tricking a user into op...
CVE-2020-21365
- EPSS 0.43%
- Published 15.08.2022 20:15:08
- Last modified 21.11.2024 05:12:32
Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations.