CVE-2022-22824
- EPSS 0.43%
- Veröffentlicht 10.01.2022 14:12:56
- Zuletzt bearbeitet 05.05.2025 17:17:53
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
CVE-2022-22825
- EPSS 0.21%
- Veröffentlicht 10.01.2022 14:12:56
- Zuletzt bearbeitet 05.05.2025 17:17:53
lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
CVE-2022-22817
- EPSS 2.78%
- Veröffentlicht 10.01.2022 14:12:55
- Zuletzt bearbeitet 21.11.2024 06:47:30
PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.
CVE-2022-22815
- EPSS 0.1%
- Veröffentlicht 10.01.2022 14:12:54
- Zuletzt bearbeitet 21.11.2024 06:47:30
path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.
CVE-2022-22816
- EPSS 0.14%
- Veröffentlicht 10.01.2022 14:12:54
- Zuletzt bearbeitet 21.11.2024 06:47:30
path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.
CVE-2021-43579
- EPSS 5.26%
- Veröffentlicht 10.01.2022 14:10:24
- Zuletzt bearbeitet 21.11.2024 06:29:28
A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file.
- EPSS 90.77%
- Veröffentlicht 10.01.2022 14:10:23
- Zuletzt bearbeitet 21.11.2024 06:27:43
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execut...
CVE-2020-29050
- EPSS 0.71%
- Veröffentlicht 10.01.2022 14:10:16
- Zuletzt bearbeitet 21.11.2024 05:23:35
SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operations on a full pathname (e.g., a file in the /etc dire...
CVE-2022-21662
- EPSS 14.24%
- Veröffentlicht 06.01.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:45:10
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can af...
CVE-2022-21663
- EPSS 0.31%
- Veröffentlicht 06.01.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:45:11
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. T...