CVE-2022-46343
- EPSS 1.26%
- Published 14.12.2022 21:15:13
- Last modified 22.04.2025 16:15:41
A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X server is...
CVE-2022-46344
- EPSS 1.06%
- Published 14.12.2022 21:15:13
- Last modified 21.11.2024 07:30:25
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length-validation issues, resulting in out-of-bounds memory reads and potential information disclosure. This issue can lead to lo...
CVE-2022-23527
- EPSS 0.38%
- Published 14.12.2022 18:15:20
- Last modified 21.11.2024 06:48:45
mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server. Versions prior to 2.4.12.2 are vulnerable to Open Redirect. When providing a logout parameter to the redirect URI, the existing code in o...
CVE-2022-23520
- EPSS 0.37%
- Published 14.12.2022 18:15:17
- Last modified 13.02.2025 17:15:38
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, there is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer due to an incomplete fix of CVE-2022-32209. R...
CVE-2022-23519
- EPSS 0.15%
- Published 14.12.2022 17:15:11
- Last modified 13.02.2025 17:15:37
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer may allow an attacker to inject content if the applica...
CVE-2022-23517
- EPSS 0.22%
- Published 14.12.2022 17:15:10
- Last modified 21.11.2024 06:48:43
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptible to excessive backtracking when attempting to san...
CVE-2022-23518
- EPSS 0.23%
- Published 14.12.2022 17:15:10
- Last modified 21.11.2024 06:48:43
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are vulnerable to cross-site scripting via data URIs when used in combination with Loofah >= 2.1.0. This issue is patched in version 1...
CVE-2022-23515
- EPSS 0.24%
- Published 14.12.2022 14:15:10
- Last modified 21.11.2024 06:48:43
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type in data URIs. This issue is pat...
CVE-2022-45685
- EPSS 0.13%
- Published 13.12.2022 15:15:11
- Last modified 22.04.2025 04:15:23
A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.
CVE-2022-45693
- EPSS 0.13%
- Published 13.12.2022 15:15:11
- Last modified 22.04.2025 15:16:05
Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted string.