CVE-2022-27384
- EPSS 0.36%
- Veröffentlicht 12.04.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:55:40
An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.
CVE-2022-27386
- EPSS 0.35%
- Veröffentlicht 12.04.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:55:40
MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.
CVE-2022-27387
- EPSS 0.25%
- Veröffentlicht 12.04.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:55:40
MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements.
CVE-2022-24070
- EPSS 0.99%
- Veröffentlicht 12.04.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:49:45
Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (i...
CVE-2022-24765
- EPSS 0.18%
- Veröffentlicht 12.04.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:51:02
Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C...
CVE-2021-28544
- EPSS 0.36%
- Veröffentlicht 12.04.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:59:49
Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, us...
CVE-2022-28347
- EPSS 1.1%
- Veröffentlicht 12.04.2022 05:15:07
- Zuletzt bearbeitet 21.11.2024 06:57:11
A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the inject...
CVE-2022-28346
- EPSS 1.97%
- Veröffentlicht 12.04.2022 05:15:06
- Zuletzt bearbeitet 21.11.2024 06:57:11
An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as...
CVE-2022-24836
- EPSS 1.38%
- Veröffentlicht 11.04.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:12
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade...
CVE-2022-28893
- EPSS 0.03%
- Veröffentlicht 11.04.2022 05:15:07
- Zuletzt bearbeitet 21.11.2024 06:58:09
The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state.