CVE-2022-0523
- EPSS 0.24%
- Veröffentlicht 08.02.2022 21:15:20
- Zuletzt bearbeitet 21.11.2024 06:38:50
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.
CVE-2022-21703
- EPSS 1.87%
- Veröffentlicht 08.02.2022 21:15:20
- Zuletzt bearbeitet 21.11.2024 06:45:16
Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated...
CVE-2022-21713
- EPSS 0.13%
- Veröffentlicht 08.02.2022 21:15:20
- Zuletzt bearbeitet 21.11.2024 06:45:17
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended ...
CVE-2022-0518
- EPSS 0.25%
- Veröffentlicht 08.02.2022 21:15:19
- Zuletzt bearbeitet 21.11.2024 06:38:49
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2.
CVE-2022-0519
- EPSS 0.37%
- Veröffentlicht 08.02.2022 21:15:19
- Zuletzt bearbeitet 21.11.2024 06:38:49
Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2.
CVE-2022-0520
- EPSS 0.34%
- Veröffentlicht 08.02.2022 21:15:19
- Zuletzt bearbeitet 21.11.2024 06:38:49
Use After Free in NPM radare2.js prior to 5.6.2.
CVE-2022-0521
- EPSS 0.37%
- Veröffentlicht 08.02.2022 21:15:19
- Zuletzt bearbeitet 21.11.2024 06:38:49
Access of Memory Location After End of Buffer in GitHub repository radareorg/radare2 prior to 5.6.2.
CVE-2022-21702
- EPSS 1.01%
- Veröffentlicht 08.02.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:45:16
Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a specially crafted link and exe...
CVE-2022-21712
- EPSS 0.21%
- Veröffentlicht 07.02.2022 22:15:08
- Zuletzt bearbeitet 25.11.2024 18:12:24
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. Br...
CVE-2022-23613
- EPSS 0.29%
- Veröffentlicht 07.02.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:48:56
xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code...