CVE-2022-0547
- EPSS 0.5%
- Veröffentlicht 18.03.2022 18:15:12
- Zuletzt bearbeitet 03.11.2025 21:15:49
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially ...
CVE-2022-1011
- EPSS 0.22%
- Veröffentlicht 18.03.2022 18:15:12
- Zuletzt bearbeitet 21.11.2024 06:39:51
A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.
CVE-2022-24302
- EPSS 0.73%
- Veröffentlicht 17.03.2022 22:15:08
- Zuletzt bearbeitet 16.12.2025 02:15:46
In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
CVE-2022-24761
- EPSS 0.35%
- Veröffentlicht 17.03.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:02
Waitress is a Web Server Gateway Interface server for Python 2 and 3. When using Waitress versions 2.1.0 and prior behind a proxy that does not properly validate the incoming HTTP request matches the RFC7230 standard, Waitress and the frontend proxy ...
CVE-2022-26353
- EPSS 0.24%
- Veröffentlicht 16.03.2022 15:15:16
- Zuletzt bearbeitet 21.11.2024 06:53:48
A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected Q...
CVE-2022-26354
- EPSS 0.02%
- Veröffentlicht 16.03.2022 15:15:16
- Zuletzt bearbeitet 21.11.2024 06:53:48
A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.
- EPSS 0.02%
- Veröffentlicht 16.03.2022 15:15:11
- Zuletzt bearbeitet 21.11.2024 06:20:04
Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel
CVE-2021-20299
- EPSS 1.03%
- Veröffentlicht 16.03.2022 15:15:10
- Zuletzt bearbeitet 21.11.2024 05:46:18
A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts can trigger a NULL pointer dereference. The highest threat from this vulnerability is to system availability.
CVE-2021-20257
- EPSS 0.08%
- Veröffentlicht 16.03.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 05:46:13
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. This flaw allows a guest to cons...
CVE-2022-27223
- EPSS 0.32%
- Veröffentlicht 16.03.2022 00:15:09
- Zuletzt bearbeitet 21.11.2024 06:55:26
In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access.