CVE-2022-41639
- EPSS 0.63%
- Veröffentlicht 22.12.2022 22:15:14
- Zuletzt bearbeitet 21.11.2024 07:23:32
A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and v2.3.19.0. A specially-crafted TIFF file can lead to an out of bounds memory corruption, which can result in arbitr...
CVE-2022-41649
- EPSS 0.18%
- Veröffentlicht 22.12.2022 22:15:14
- Zuletzt bearbeitet 21.11.2024 07:23:33
A heap out of bounds read vulnerability exists in the handling of IPTC data while parsing TIFF images in OpenImageIO v2.3.19.0. A specially-crafted TIFF file can cause a read of adjacent heap memory, which can leak sensitive process information. An a...
CVE-2022-36354
- EPSS 0.11%
- Veröffentlicht 22.12.2022 22:15:13
- Zuletzt bearbeitet 21.11.2024 07:12:51
A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.19.0. More specifically, in the way run-length encoded byte spans are handled. A malformed RLA file can lead to an out-of-bounds re...
CVE-2022-46877
- EPSS 0.48%
- Veröffentlicht 22.12.2022 20:15:46
- Zuletzt bearbeitet 15.04.2025 14:15:37
By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 108.
CVE-2022-46871
- EPSS 0.93%
- Veröffentlicht 22.12.2022 20:15:45
- Zuletzt bearbeitet 15.04.2025 15:16:05
An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.
CVE-2022-47629
- EPSS 1.53%
- Veröffentlicht 20.12.2022 23:15:12
- Zuletzt bearbeitet 16.04.2025 18:16:02
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
CVE-2022-4515
- EPSS 1.03%
- Veröffentlicht 20.12.2022 19:15:25
- Zuletzt bearbeitet 14.04.2025 19:15:35
A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the ex...
CVE-2022-23537
- EPSS 0.37%
- Veröffentlicht 20.12.2022 19:15:24
- Zuletzt bearbeitet 04.11.2025 16:15:46
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. Buffer overread is possible when parsing a specially crafted STUN message with un...
CVE-2022-47518
- EPSS 0.03%
- Veröffentlicht 18.12.2022 06:15:09
- Zuletzt bearbeitet 17.04.2025 15:15:52
An issue was discovered in the Linux kernel before 6.0.11. Missing validation of the number of channels in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when copying the li...
CVE-2022-47519
- EPSS 0.1%
- Veröffentlicht 18.12.2022 06:15:09
- Zuletzt bearbeitet 17.04.2025 15:15:52
An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_OPER_CHANNEL in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger an out-of-bounds write when parsing the...