CVE-2022-23837
- EPSS 0.99%
- Veröffentlicht 21.01.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:49:20
In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.
CVE-2021-23518
- EPSS 0.13%
- Veröffentlicht 21.01.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:51:48
The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties whe...
CVE-2022-0319
- EPSS 0.17%
- Veröffentlicht 21.01.2022 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:38:22
Out-of-bounds Read in vim/vim prior to 8.2.
CVE-2022-0318
- EPSS 0.2%
- Veröffentlicht 21.01.2022 12:15:10
- Zuletzt bearbeitet 21.11.2024 06:38:22
Heap-based Buffer Overflow in vim/vim prior to 8.2.
CVE-2021-45417
- EPSS 0.04%
- Veröffentlicht 20.01.2022 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:10
AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.
CVE-2022-21704
- EPSS 0.04%
- Veröffentlicht 19.01.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:45:16
log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log files contain sensitive inform...
CVE-2022-21699
- EPSS 1.46%
- Veröffentlicht 19.01.2022 22:15:09
- Zuletzt bearbeitet 21.11.2024 06:45:15
IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved...
CVE-2021-23225
- EPSS 0.81%
- Veröffentlicht 19.01.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:24
Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php.
CVE-2021-33912
- EPSS 1.35%
- Veröffentlicht 19.01.2022 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:09:45
libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of incorrect spr...
- EPSS 22.2%
- Veröffentlicht 19.01.2022 17:15:09
- Zuletzt bearbeitet 05.05.2025 17:17:56
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.