CVE-2022-23033
- EPSS 0.09%
- Veröffentlicht 25.01.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:47:50
arm: guest_physmap_remove_page not removing the p2m mappings The functions to remove one or more entries from a guest p2m pagetable on Arm (p2m_remove_mapping, guest_physmap_remove_page, and p2m_set_entry with mfn set to INVALID_MFN) do not actually ...
CVE-2021-45845
- EPSS 1.54%
- Veröffentlicht 25.01.2022 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:33:08
The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbitrary commands via a crafted FCStd document.
CVE-2021-45342
- EPSS 2.35%
- Veröffentlicht 25.01.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:07
A buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.
CVE-2021-45343
- EPSS 0.16%
- Veröffentlicht 25.01.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:07
In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted DXF document.
CVE-2021-45844
- EPSS 0.34%
- Veröffentlicht 25.01.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:33:08
Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.
CVE-2021-45341
- EPSS 4.61%
- Veröffentlicht 25.01.2022 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:32:06
A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.
CVE-2022-23852
- EPSS 1.71%
- Veröffentlicht 24.01.2022 02:15:06
- Zuletzt bearbeitet 05.05.2025 17:17:58
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.
CVE-2022-23837
- EPSS 0.81%
- Veröffentlicht 21.01.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:49:20
In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.
CVE-2021-23518
- EPSS 0.65%
- Veröffentlicht 21.01.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:51:48
The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties whe...
CVE-2022-0319
- EPSS 0.17%
- Veröffentlicht 21.01.2022 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:38:22
Out-of-bounds Read in vim/vim prior to 8.2.