CVE-2022-23125
- EPSS 20.05%
- Veröffentlicht 28.03.2023 19:15:10
- Zuletzt bearbeitet 04.11.2025 20:16:03
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyapplfile function. When parsing the len ...
CVE-2022-0194
- EPSS 9.3%
- Veröffentlicht 28.03.2023 19:15:09
- Zuletzt bearbeitet 04.11.2025 20:16:03
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ad_addcomment function. The issue results fr...
- EPSS 0.02%
- Veröffentlicht 27.03.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:38:24
In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy error condition would lead to a type confused entry with the list head,...
CVE-2023-1380
- EPSS 0.02%
- Veröffentlicht 27.03.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:39:04
A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined ...
CVE-2023-28686
- EPSS 0.16%
- Veröffentlicht 24.03.2023 04:15:55
- Zuletzt bearbeitet 19.02.2025 22:15:16
Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then...
CVE-2023-0386
- EPSS 50.57%
- Veröffentlicht 22.03.2023 21:15:18
- Zuletzt bearbeitet 04.11.2025 16:47:21
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This...
CVE-2022-42333
- EPSS 0.42%
- Veröffentlicht 21.03.2023 13:15:12
- Zuletzt bearbeitet 21.11.2024 07:24:46
x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an ...
CVE-2022-42334
- EPSS 0.05%
- Veröffentlicht 21.03.2023 13:15:12
- Zuletzt bearbeitet 21.11.2024 07:24:46
x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an ...
CVE-2022-42332
- EPSS 0.05%
- Veröffentlicht 21.03.2023 13:15:11
- Zuletzt bearbeitet 21.11.2024 07:24:46
x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Shadow mode maintains a pool of memory...
- EPSS 0.02%
- Veröffentlicht 16.03.2023 00:15:11
- Zuletzt bearbeitet 05.05.2025 16:15:34
do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference).