- EPSS 0.37%
- Published 07.06.2022 18:15:10
- Last modified 21.11.2024 04:52:42
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo with the tcpdump command, without a password. This occurs because the -z (aka postrotate-command) option to tcpd...
- EPSS 0.45%
- Published 07.06.2022 18:15:10
- Last modified 21.11.2024 04:52:42
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the phonesystem user privileges because of "<space><space> followed by <shift><enter>" mishandling.
CVE-2022-32250
- EPSS 2.1%
- Published 02.06.2022 21:15:07
- Last modified 21.11.2024 07:06:01
net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.
CVE-2022-31799
- EPSS 0.29%
- Published 02.06.2022 14:15:58
- Last modified 21.11.2024 07:05:21
Bottle before 0.12.20 mishandles errors during early request binding.
CVE-2022-27781
- EPSS 0.19%
- Published 02.06.2022 14:15:44
- Last modified 21.11.2024 06:56:10
libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS get stuck in a never-ending bus...
CVE-2022-27782
- EPSS 0.47%
- Published 02.06.2022 14:15:44
- Last modified 21.11.2024 06:56:10
libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them...
CVE-2022-27774
- EPSS 0.29%
- Published 02.06.2022 14:15:43
- Last modified 21.11.2024 06:56:09
An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to ...
CVE-2022-27775
- EPSS 0.14%
- Published 02.06.2022 14:15:43
- Last modified 21.11.2024 06:56:09
An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.
CVE-2022-27776
- EPSS 0.99%
- Published 02.06.2022 14:15:43
- Last modified 21.11.2024 06:56:09
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
CVE-2022-26491
- EPSS 0.49%
- Published 02.06.2022 14:15:40
- Last modified 21.11.2024 06:54:02
An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client connection to a malicious server. The client will perform TLS certificate verification of the malicious domain name instead of the or...