CVE-2022-21712
- EPSS 0.17%
- Published 07.02.2022 22:15:08
- Last modified 25.11.2024 18:12:24
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. Br...
CVE-2022-23614
- EPSS 45.72%
- Published 04.02.2022 23:15:15
- Last modified 21.11.2024 06:48:56
Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly...
CVE-2022-23946
- EPSS 0.75%
- Published 04.02.2022 23:15:15
- Last modified 21.11.2024 06:49:30
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An ...
CVE-2022-23947
- EPSS 0.55%
- Published 04.02.2022 23:15:15
- Last modified 21.11.2024 06:49:30
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An ...
CVE-2021-4043
- EPSS 0.94%
- Published 04.02.2022 23:15:12
- Last modified 21.11.2024 06:36:47
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0.
CVE-2022-0487
- EPSS 0.05%
- Published 04.02.2022 23:15:12
- Last modified 21.11.2024 06:38:45
A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidentiality. This flaw affects kerne...
CVE-2021-40401
- EPSS 0.28%
- Published 04.02.2022 23:15:11
- Last modified 21.11.2024 06:24:03
A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a...
CVE-2021-40403
- EPSS 0.13%
- Published 04.02.2022 23:15:11
- Last modified 21.11.2024 06:24:03
An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a ...
CVE-2021-46671
- EPSS 0.12%
- Published 04.02.2022 21:15:08
- Last modified 21.11.2024 06:34:34
options.c in atftp before 0.7.5 reads past the end of an array, and consequently discloses server-side /etc/group data to a remote client.
CVE-2022-24448
- EPSS 0.01%
- Published 04.02.2022 20:15:08
- Last modified 21.11.2024 06:50:26
An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR should occur, b...