CVE-2022-25236
- EPSS 10.89%
- Veröffentlicht 16.02.2022 01:15:07
- Zuletzt bearbeitet 05.05.2025 17:18:01
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
CVE-2022-0583
- EPSS 0.1%
- Veröffentlicht 14.02.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:38:58
Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
CVE-2022-0586
- EPSS 0.03%
- Veröffentlicht 14.02.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:38:58
Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
CVE-2022-0581
- EPSS 0.09%
- Veröffentlicht 14.02.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:38:57
Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
CVE-2022-0582
- EPSS 0.07%
- Veröffentlicht 14.02.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:38:57
Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
CVE-2022-0572
- EPSS 0.92%
- Veröffentlicht 14.02.2022 12:15:23
- Zuletzt bearbeitet 21.11.2024 06:38:56
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVE-2021-45444
- EPSS 0.11%
- Veröffentlicht 14.02.2022 12:15:15
- Zuletzt bearbeitet 21.11.2024 06:32:13
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
CVE-2022-23634
- EPSS 0.44%
- Veröffentlicht 11.02.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:48:58
Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5.6.2`, `puma` may not always call `close` on the response body. Rails, prior to version `7.0.2.2`, depended on the response body being closed in order for its `CurrentAtt...
CVE-2022-23633
- EPSS 0.24%
- Veröffentlicht 11.02.2022 21:15:11
- Zuletzt bearbeitet 21.11.2024 06:48:58
Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread l...
CVE-2021-20001
- EPSS 0.77%
- Veröffentlicht 11.02.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:45:46
It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which could result in privilege escalation.