CVE-2022-39955
- EPSS 0.16%
- Veröffentlicht 20.09.2022 07:15:12
- Zuletzt bearbeitet 03.11.2025 20:15:56
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field that indicates multiple character encoding schemes. A vulnerable back-end can potentially be exploited...
CVE-2022-39956
- EPSS 0.12%
- Veröffentlicht 20.09.2022 07:15:12
- Zuletzt bearbeitet 03.11.2025 20:15:56
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MI...
CVE-2022-39957
- EPSS 0.09%
- Veröffentlicht 20.09.2022 07:15:12
- Zuletzt bearbeitet 03.11.2025 20:15:56
The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded form. Depending on the "charset"...
CVE-2022-39958
- EPSS 0.21%
- Veröffentlicht 20.09.2022 07:15:12
- Zuletzt bearbeitet 03.11.2025 20:15:56
The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by repeatedly submitting an HTTP Range header field with a small byte range. A restricted resource, acc...
CVE-2022-37032
- EPSS 0.84%
- Veröffentlicht 19.09.2022 22:15:11
- Zuletzt bearbeitet 21.11.2024 07:14:19
An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.
CVE-2022-28201
- EPSS 0.07%
- Veröffentlicht 19.09.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:56:56
An issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. Users with the editinterface permission can trigger infinite recursion, because a bare local interwiki is mishandled for the mainpage message.
CVE-2022-28203
- EPSS 0.42%
- Veröffentlicht 19.09.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:56:56
A denial-of-service issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. When many files exist, requesting Special:NewFiles with actor as a condition can result in a very long running query.
CVE-2022-3235
- EPSS 0.07%
- Veröffentlicht 18.09.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 07:19:06
Use After Free in GitHub repository vim/vim prior to 9.0.0490.
CVE-2022-40768
- EPSS 0.02%
- Veröffentlicht 18.09.2022 05:15:08
- Zuletzt bearbeitet 21.11.2024 07:22:01
drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case.
CVE-2022-3234
- EPSS 0.06%
- Veröffentlicht 17.09.2022 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:19:06
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.