CVE-2022-30784
- EPSS 0.03%
- Veröffentlicht 26.05.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 07:03:22
A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22.
CVE-2022-30785
- EPSS 0.01%
- Veröffentlicht 26.05.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 07:03:22
A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.
CVE-2022-30786
- EPSS 0.04%
- Veröffentlicht 26.05.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 07:03:22
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22.
CVE-2022-1664
- EPSS 0.38%
- Veröffentlicht 26.05.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:41:12
Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that i...
CVE-2022-29248
- EPSS 0.45%
- Veröffentlicht 25.05.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:58:48
Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the domain of the server which sets the cookie via the ...
CVE-2022-1851
- EPSS 0.13%
- Veröffentlicht 25.05.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:41:36
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
CVE-2022-29221
- EPSS 23.37%
- Veröffentlicht 24.05.2022 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:58:44
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {block} name or {include} file name...
CVE-2022-29599
- EPSS 0.4%
- Veröffentlicht 23.05.2022 11:16:10
- Zuletzt bearbeitet 21.11.2024 06:59:23
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
CVE-2022-1785
- EPSS 0.03%
- Veröffentlicht 19.05.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:41:27
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977.
- EPSS 0.01%
- Veröffentlicht 18.05.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:41:21
A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine.