CVE-2020-27792
- EPSS 0.05%
- Veröffentlicht 19.08.2022 23:15:08
- Zuletzt bearbeitet 30.04.2025 10:15:15
A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could l...
CVE-2022-26373
- EPSS 0.11%
- Veröffentlicht 18.08.2022 20:15:11
- Zuletzt bearbeitet 05.05.2025 17:18:03
Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
CVE-2021-32862
- EPSS 0.79%
- Veröffentlicht 18.08.2022 19:15:14
- Zuletzt bearbeitet 21.11.2024 06:07:54
The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to ...
CVE-2022-2867
- EPSS 0.03%
- Veröffentlicht 17.08.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:01:50
libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who supplies a crafted file to tiffcrop (likely via tricking a user to run tiffcrop on it with certain parameters) could cause a crash or i...
CVE-2022-2868
- EPSS 0.03%
- Veröffentlicht 17.08.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:01:50
libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is able to supply a crafted file to tiffcrop.
CVE-2022-2869
- EPSS 0.03%
- Veröffentlicht 17.08.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:01:50
libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples8bits routine. An attacker who supplies a crafted file to tiffcrop could trigger this flaw, most likely by tricking a user into op...
CVE-2020-21365
- EPSS 0.47%
- Veröffentlicht 15.08.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:12:32
Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations.
CVE-2022-20369
- EPSS 0.03%
- Veröffentlicht 11.08.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:42:41
In v4l2_m2m_querybuf of v4l2-mem2mem.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitatio...
CVE-2021-37150
- EPSS 1.16%
- Veröffentlicht 10.08.2022 06:15:08
- Zuletzt bearbeitet 08.09.2025 19:15:31
Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
CVE-2022-25763
- EPSS 0.44%
- Veröffentlicht 10.08.2022 06:15:08
- Zuletzt bearbeitet 20.10.2025 18:15:36
Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.