- EPSS 0.01%
- Veröffentlicht 29.04.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:39:55
A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. This flaw allows a local user t...
CVE-2022-1195
- EPSS 0.02%
- Veröffentlicht 29.04.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:40:13
A use-after-free vulnerability was found in the Linux kernel in drivers/net/hamradio. This flaw allows a local attacker with a user privilege to cause a denial of service (DOS) when the mkiss or sixpack device is detached and reclaim resources early.
CVE-2022-1353
- EPSS 0.02%
- Veröffentlicht 29.04.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:40:33
A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information.
CVE-2022-29869
- EPSS 0.85%
- Veröffentlicht 28.04.2022 01:15:06
- Zuletzt bearbeitet 21.11.2024 06:59:51
cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.
CVE-2022-27239
- EPSS 0.07%
- Veröffentlicht 27.04.2022 14:15:09
- Zuletzt bearbeitet 21.11.2024 06:55:28
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
CVE-2022-1441
- EPSS 0.14%
- Veröffentlicht 25.04.2022 17:15:36
- Zuletzt bearbeitet 21.11.2024 06:40:44
MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it allocates a buffer `str` with fixed...
CVE-2022-24792
- EPSS 1.62%
- Veröffentlicht 25.04.2022 16:16:09
- Zuletzt bearbeitet 21.11.2024 06:51:06
PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects applications on a 32-bit systems that use PJSIP versions 2.12 and prior to play/read invalid WAV files. The vulnerability occurs ...
CVE-2019-25059
- EPSS 0.17%
- Veröffentlicht 25.04.2022 04:15:07
- Zuletzt bearbeitet 21.11.2024 04:39:51
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
- EPSS 0.18%
- Veröffentlicht 22.04.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:59:20
In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploit...
CVE-2022-29536
- EPSS 0.15%
- Veröffentlicht 20.04.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:17
In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is...