CVE-2022-27114
- EPSS 0.2%
- Veröffentlicht 09.05.2022 17:15:09
- Zuletzt bearbeitet 21.11.2024 06:55:10
There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and 'img->height' they are large enough to cause an integer overflow. So, the malloc function may return a heap blosmaller than the ex...
CVE-2022-30333
- EPSS 92.84%
- Veröffentlicht 09.05.2022 08:15:06
- Zuletzt bearbeitet 03.11.2025 16:20:12
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
CVE-2022-28463
- EPSS 0.13%
- Veröffentlicht 08.05.2022 23:15:17
- Zuletzt bearbeitet 25.06.2025 21:02:38
ImageMagick 7.1.0-27 is vulnerable to Buffer Overflow.
CVE-2022-1619
- EPSS 0.5%
- Veröffentlicht 08.05.2022 10:15:07
- Zuletzt bearbeitet 21.11.2024 06:41:06
Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution
CVE-2018-25033
- EPSS 0.48%
- Veröffentlicht 08.05.2022 06:15:06
- Zuletzt bearbeitet 21.11.2024 04:03:24
ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from stl_remove_degenerate) in connect.c in libadmesh.a.
CVE-2022-1616
- EPSS 0.09%
- Veröffentlicht 07.05.2022 19:15:07
- Zuletzt bearbeitet 03.11.2025 21:15:50
Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
CVE-2022-30293
- EPSS 0.19%
- Veröffentlicht 06.05.2022 05:15:07
- Zuletzt bearbeitet 21.11.2024 07:02:31
In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.
CVE-2022-24884
- EPSS 0.12%
- Veröffentlicht 06.05.2022 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:19
ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signature values `r` and `s` are non-zero. A signature consisting only of zeroes is always considered vali...
CVE-2022-24903
- EPSS 0.78%
- Veröffentlicht 06.05.2022 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:21
Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when octet-counted framing is used. This can result in a segfault or some other malfunction. As of our understanding, this vuln...
CVE-2022-27337
- EPSS 0.24%
- Veröffentlicht 05.05.2022 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:55:36
A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.