CVE-2022-31625
- EPSS 0.77%
- Veröffentlicht 16.06.2022 06:15:08
- Zuletzt bearbeitet 21.11.2024 07:04:52
In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointe...
CVE-2022-31626
- EPSS 10.24%
- Veröffentlicht 16.06.2022 06:15:08
- Zuletzt bearbeitet 21.11.2024 07:04:53
In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length ...
CVE-2022-21166
- EPSS 0.19%
- Veröffentlicht 15.06.2022 21:15:09
- Zuletzt bearbeitet 05.05.2025 17:17:41
Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
CVE-2022-21123
- EPSS 0.45%
- Veröffentlicht 15.06.2022 20:15:17
- Zuletzt bearbeitet 05.05.2025 17:17:37
Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
CVE-2022-21125
- EPSS 0.24%
- Veröffentlicht 15.06.2022 20:15:17
- Zuletzt bearbeitet 05.05.2025 17:17:37
Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
CVE-2022-21127
- EPSS 0.28%
- Veröffentlicht 15.06.2022 20:15:17
- Zuletzt bearbeitet 05.05.2025 17:17:37
Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
CVE-2022-32278
- EPSS 0.81%
- Veröffentlicht 13.06.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:06:05
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
CVE-2022-31042
- EPSS 1.45%
- Veröffentlicht 10.06.2022 00:15:07
- Zuletzt bearbeitet 21.11.2024 07:03:46
Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` scheme, or on ...
CVE-2022-31043
- EPSS 1.45%
- Veröffentlicht 10.06.2022 00:15:07
- Zuletzt bearbeitet 21.11.2024 07:03:46
Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` scheme, we ...
CVE-2022-21499
- EPSS 0.18%
- Veröffentlicht 09.06.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:44:50
KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker with access to a serial port could trigger the debugger so it is important that the debugger respect the lockdown mode when/if it is...