CVE-2022-28041
- EPSS 1.03%
- Veröffentlicht 15.04.2022 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:56:39
stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
CVE-2022-28042
- EPSS 0.43%
- Veröffentlicht 15.04.2022 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:56:40
stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode.
CVE-2022-28044
- EPSS 0.74%
- Veröffentlicht 15.04.2022 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:56:40
Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control.
CVE-2022-26498
- EPSS 0.31%
- Veröffentlicht 15.04.2022 05:15:06
- Zuletzt bearbeitet 21.11.2024 06:54:03
An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not certificates. These files could be much larger than what one would expect to download, leading to Resource Exhaustion. This is fix...
CVE-2022-26499
- EPSS 0.36%
- Veröffentlicht 15.04.2022 05:15:06
- Zuletzt bearbeitet 21.11.2024 06:54:03
An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2.
CVE-2022-26651
- EPSS 0.44%
- Veröffentlicht 15.04.2022 05:15:06
- Zuletzt bearbeitet 21.11.2024 06:54:15
An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escaping functionality for backslash characters in SQL queries, resulting in user-provided data creating a ...
CVE-2022-1328
- EPSS 0.22%
- Veröffentlicht 14.04.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:40:29
Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line
CVE-2022-27452
- EPSS 0.14%
- Veröffentlicht 14.04.2022 13:15:12
- Zuletzt bearbeitet 21.11.2024 06:55:45
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.cc.
CVE-2022-27456
- EPSS 0.14%
- Veröffentlicht 14.04.2022 13:15:12
- Zuletzt bearbeitet 21.11.2024 06:55:46
MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc.
CVE-2022-27445
- EPSS 0.31%
- Veröffentlicht 14.04.2022 13:15:11
- Zuletzt bearbeitet 21.11.2024 06:55:44
MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/sql_window.cc.