CVE-2022-40307
- EPSS 0.03%
- Veröffentlicht 09.09.2022 05:15:07
- Zuletzt bearbeitet 21.11.2024 07:21:16
An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition with a resultant use-after-free.
CVE-2022-40023
- EPSS 1.01%
- Veröffentlicht 07.09.2022 13:15:09
- Zuletzt bearbeitet 03.12.2025 07:16:01
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
CVE-2022-3134
- EPSS 0.05%
- Veröffentlicht 06.09.2022 20:15:09
- Zuletzt bearbeitet 03.11.2025 21:15:53
Use After Free in GitHub repository vim/vim prior to 9.0.0389.
CVE-2022-2735
- EPSS 0.04%
- Veröffentlicht 06.09.2022 18:15:14
- Zuletzt bearbeitet 21.11.2024 07:01:36
A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an authentication token for a hacluste...
CVE-2022-38749
- EPSS 0.53%
- Veröffentlicht 05.09.2022 10:15:09
- Zuletzt bearbeitet 21.11.2024 07:17:01
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.
CVE-2022-38750
- EPSS 0.16%
- Veröffentlicht 05.09.2022 10:15:09
- Zuletzt bearbeitet 21.11.2024 07:17:01
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.
CVE-2022-38751
- EPSS 0.21%
- Veröffentlicht 05.09.2022 10:15:09
- Zuletzt bearbeitet 21.11.2024 07:17:01
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.
CVE-2022-3008
- EPSS 7.64%
- Veröffentlicht 05.09.2022 09:15:10
- Zuletzt bearbeitet 21.11.2024 07:18:37
The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. This function allows for command injection by using backticks. An attacker could craft an untrusted pa...
CVE-2022-39842
- EPSS 0.01%
- Veröffentlicht 05.09.2022 07:15:08
- Zuletzt bearbeitet 21.11.2024 07:18:22
An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer overflow and bypassing the size check. After that, beca...
CVE-2022-3099
- EPSS 0.1%
- Veröffentlicht 03.09.2022 16:15:08
- Zuletzt bearbeitet 03.11.2025 21:15:53
Use After Free in GitHub repository vim/vim prior to 9.0.0360.