CVE-2022-38398
- EPSS 0.17%
- Veröffentlicht 22.09.2022 15:15:09
- Zuletzt bearbeitet 03.11.2025 20:15:56
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14.
CVE-2022-38648
- EPSS 0.17%
- Veröffentlicht 22.09.2022 15:15:09
- Zuletzt bearbeitet 03.11.2025 20:15:56
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.
CVE-2022-40146
- EPSS 41.22%
- Veröffentlicht 22.09.2022 15:15:09
- Zuletzt bearbeitet 03.11.2025 20:15:57
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14.
CVE-2022-3256
- EPSS 0.06%
- Veröffentlicht 22.09.2022 13:15:09
- Zuletzt bearbeitet 21.11.2024 07:19:09
Use After Free in GitHub repository vim/vim prior to 9.0.0530.
CVE-2022-2795
- EPSS 0.49%
- Veröffentlicht 21.09.2022 11:15:09
- Zuletzt bearbeitet 29.11.2024 12:15:04
By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.
CVE-2022-38177
- EPSS 1.16%
- Veröffentlicht 21.09.2022 11:15:09
- Zuletzt bearbeitet 28.05.2025 16:15:26
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
CVE-2022-38178
- EPSS 1.42%
- Veröffentlicht 21.09.2022 11:15:09
- Zuletzt bearbeitet 28.05.2025 16:15:26
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
- EPSS 0.02%
- Veröffentlicht 21.09.2022 08:15:09
- Zuletzt bearbeitet 28.05.2025 16:15:28
mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move.
CVE-2022-41218
- EPSS 0.43%
- Veröffentlicht 21.09.2022 07:15:08
- Zuletzt bearbeitet 28.05.2025 16:15:28
In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release.
CVE-2022-32886
- EPSS 0.88%
- Veröffentlicht 20.09.2022 21:15:11
- Zuletzt bearbeitet 29.05.2025 15:15:21
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution.