CVE-2022-24785
- EPSS 0.83%
- Veröffentlicht 04.04.2022 17:15:07
- Zuletzt bearbeitet 03.11.2025 22:15:57
Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string ...
CVE-2022-24191
- EPSS 0.04%
- Veröffentlicht 04.04.2022 11:15:08
- Zuletzt bearbeitet 21.11.2024 06:49:58
In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow.
CVE-2022-28388
- EPSS 0.01%
- Veröffentlicht 03.04.2022 21:15:08
- Zuletzt bearbeitet 05.05.2025 17:18:07
usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free.
CVE-2022-28389
- EPSS 0.02%
- Veröffentlicht 03.04.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:57:16
mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free.
CVE-2022-28390
- EPSS 0.01%
- Veröffentlicht 03.04.2022 21:15:08
- Zuletzt bearbeitet 25.06.2025 21:00:27
ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.
CVE-2021-3847
- EPSS 0.04%
- Veröffentlicht 01.04.2022 23:15:10
- Zuletzt bearbeitet 21.11.2024 06:22:38
An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to esc...
CVE-2022-24790
- EPSS 0.51%
- Veröffentlicht 30.03.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:06
Puma is a simple, fast, multi-threaded, parallel HTTP 1.1 server for Ruby/Rack applications. When using Puma behind a proxy that does not properly validate that the incoming HTTP request matches the RFC7230 standard, Puma and the frontend proxy may d...
CVE-2022-1160
- EPSS 0.14%
- Veröffentlicht 30.03.2022 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:40:09
heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.
CVE-2022-1154
- EPSS 0.6%
- Veröffentlicht 30.03.2022 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:40:08
Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.
CVE-2022-28202
- EPSS 0.4%
- Veröffentlicht 30.03.2022 06:15:06
- Zuletzt bearbeitet 21.11.2024 06:56:56
An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete.