CVE-2022-46149
- EPSS 0.1%
- Veröffentlicht 30.11.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 07:30:12
Cap'n Proto is a data interchange format and remote procedure call (RPC) system. Cap'n Proro prior to versions 0.7.1, 0.8.1, 0.9.2, and 0.10.3, as well as versions of Cap'n Proto's Rust implementation prior to 0.13.7, 0.14.11, and 0.15.2 are vulnerab...
CVE-2022-4144
- EPSS 0.01%
- Veröffentlicht 29.11.2022 18:15:10
- Zuletzt bearbeitet 14.04.2025 18:15:24
An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into a...
CVE-2022-4172
- EPSS 0.03%
- Veröffentlicht 29.11.2022 18:15:10
- Zuletzt bearbeitet 14.04.2025 18:15:25
An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to overrun the host buffer alloc...
CVE-2022-4129
- EPSS 0.02%
- Veröffentlicht 28.11.2022 22:15:11
- Zuletzt bearbeitet 14.04.2025 18:15:24
A flaw was found in the Linux kernel's Layer 2 Tunneling Protocol (L2TP). A missing lock when clearing sk_user_data can lead to a race condition and NULL pointer dereference. A local user could use this flaw to potentially crash the system causing a ...
CVE-2022-45939
- EPSS 0.04%
- Veröffentlicht 28.11.2022 06:15:10
- Zuletzt bearbeitet 28.04.2025 19:15:46
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For example, a victim may u...
CVE-2022-45934
- EPSS 0.33%
- Veröffentlicht 27.11.2022 04:15:10
- Zuletzt bearbeitet 29.04.2025 14:15:30
An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets.
CVE-2022-45152
- EPSS 0.74%
- Veröffentlicht 25.11.2022 19:15:12
- Zuletzt bearbeitet 29.04.2025 15:15:52
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in...
CVE-2022-39346
- EPSS 0.23%
- Veröffentlicht 25.11.2022 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:18:05
Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a denial of service. It is recomm...
CVE-2022-4141
- EPSS 0.03%
- Veröffentlicht 25.11.2022 14:15:10
- Zuletzt bearbeitet 21.11.2024 07:34:39
Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.
CVE-2022-45873
- EPSS 0.02%
- Veröffentlicht 23.11.2022 23:15:10
- Zuletzt bearbeitet 25.04.2025 19:15:48
systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same fu...