CVE-2022-31629
- EPSS 32.04%
- Veröffentlicht 28.09.2022 23:15:10
- Zuletzt bearbeitet 21.11.2024 07:04:53
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.
CVE-2022-31628
- EPSS 0.03%
- Veröffentlicht 28.09.2022 23:15:09
- Zuletzt bearbeitet 21.11.2024 07:04:53
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.
CVE-2022-1270
- EPSS 0.04%
- Veröffentlicht 28.09.2022 20:15:10
- Zuletzt bearbeitet 21.05.2025 15:15:55
In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.
CVE-2022-39261
- EPSS 1.57%
- Veröffentlicht 28.09.2022 14:15:10
- Zuletzt bearbeitet 21.11.2024 07:17:54
Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. It is possible to use the `source` or `in...
CVE-2021-43980
- EPSS 0.22%
- Veröffentlicht 28.09.2022 14:15:09
- Zuletzt bearbeitet 21.05.2025 15:15:55
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10...
CVE-2022-32166
- EPSS 0.47%
- Veröffentlicht 28.09.2022 10:15:09
- Zuletzt bearbeitet 21.05.2025 15:15:56
In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory m...
CVE-2022-3303
- EPSS 0.02%
- Veröffentlicht 27.09.2022 23:15:15
- Zuletzt bearbeitet 21.05.2025 16:15:28
A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL pointer dereference while handling the SNDCTL_DSP_SYNC ioctl. A privileged local user (root or member of the audio group) could use t...
CVE-2022-3324
- EPSS 0.05%
- Veröffentlicht 27.09.2022 23:15:15
- Zuletzt bearbeitet 21.11.2024 07:19:17
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.
CVE-2022-3201
- EPSS 0.11%
- Veröffentlicht 26.09.2022 16:15:13
- Zuletzt bearbeitet 21.11.2024 07:19:02
Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page. (Chromiu...
CVE-2022-21797
- EPSS 0.19%
- Veröffentlicht 26.09.2022 05:15:10
- Zuletzt bearbeitet 21.11.2024 06:45:27
The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.