CVE-2022-25647
- EPSS 2.66%
- Published 01.05.2022 16:15:08
- Last modified 21.11.2024 06:52:30
The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.
CVE-2021-4206
- EPSS 0.17%
- Published 29.04.2022 17:15:20
- Last modified 21.03.2025 18:15:27
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious pri...
CVE-2021-4207
- EPSS 0.05%
- Published 29.04.2022 17:15:20
- Last modified 21.03.2025 18:15:28
A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer ...
- EPSS 0.01%
- Published 29.04.2022 16:15:08
- Last modified 21.11.2024 06:39:55
A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. This flaw allows a local user t...
CVE-2022-1195
- EPSS 0.02%
- Published 29.04.2022 16:15:08
- Last modified 21.11.2024 06:40:13
A use-after-free vulnerability was found in the Linux kernel in drivers/net/hamradio. This flaw allows a local attacker with a user privilege to cause a denial of service (DOS) when the mkiss or sixpack device is detached and reclaim resources early.
CVE-2022-1353
- EPSS 0.01%
- Published 29.04.2022 16:15:08
- Last modified 21.11.2024 06:40:33
A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information.
CVE-2022-29869
- EPSS 1.18%
- Published 28.04.2022 01:15:06
- Last modified 21.11.2024 06:59:51
cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.
CVE-2022-27239
- EPSS 0.12%
- Published 27.04.2022 14:15:09
- Last modified 21.11.2024 06:55:28
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
CVE-2022-1441
- EPSS 0.14%
- Published 25.04.2022 17:15:36
- Last modified 21.11.2024 06:40:44
MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it allocates a buffer `str` with fixed...
CVE-2022-24792
- EPSS 0.33%
- Published 25.04.2022 16:16:09
- Last modified 21.11.2024 06:51:06
PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects applications on a 32-bit systems that use PJSIP versions 2.12 and prior to play/read invalid WAV files. The vulnerability occurs ...