CVE-2022-1623
- EPSS 0.08%
- Veröffentlicht 11.05.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:41:07
LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:624, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.
CVE-2022-1621
- EPSS 0.31%
- Veröffentlicht 10.05.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:41:06
Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
CVE-2022-28739
- EPSS 0.51%
- Veröffentlicht 09.05.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:57:50
There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x before 3.1.2. It occurs in String-to-Float conversion, including Kernel#Float and String#to_f.
CVE-2022-27114
- EPSS 0.12%
- Veröffentlicht 09.05.2022 17:15:09
- Zuletzt bearbeitet 21.11.2024 06:55:10
There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and 'img->height' they are large enough to cause an integer overflow. So, the malloc function may return a heap blosmaller than the ex...
CVE-2022-30333
- EPSS 90.45%
- Veröffentlicht 09.05.2022 08:15:06
- Zuletzt bearbeitet 13.03.2025 15:35:00
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
CVE-2022-28463
- EPSS 0.08%
- Veröffentlicht 08.05.2022 23:15:17
- Zuletzt bearbeitet 25.06.2025 21:02:38
ImageMagick 7.1.0-27 is vulnerable to Buffer Overflow.
CVE-2022-1619
- EPSS 0.71%
- Veröffentlicht 08.05.2022 10:15:07
- Zuletzt bearbeitet 21.11.2024 06:41:06
Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution
CVE-2018-25033
- EPSS 0.46%
- Veröffentlicht 08.05.2022 06:15:06
- Zuletzt bearbeitet 21.11.2024 04:03:24
ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from stl_remove_degenerate) in connect.c in libadmesh.a.
CVE-2022-1616
- EPSS 0.1%
- Veröffentlicht 07.05.2022 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:41:05
Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
CVE-2022-30293
- EPSS 0.16%
- Veröffentlicht 06.05.2022 05:15:07
- Zuletzt bearbeitet 21.11.2024 07:02:31
In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.