CVE-2022-44789
- EPSS 4.42%
- Veröffentlicht 23.11.2022 21:15:11
- Zuletzt bearbeitet 25.04.2025 20:15:35
A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.
CVE-2022-45866
- EPSS 0.62%
- Veröffentlicht 23.11.2022 20:15:10
- Zuletzt bearbeitet 25.04.2025 19:15:47
qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allows directory traversal via ../ in a .qp file.
CVE-2022-45149
- EPSS 0.26%
- Veröffentlicht 23.11.2022 15:15:10
- Zuletzt bearbeitet 25.04.2025 20:15:35
A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they have just restored. A ...
CVE-2022-45150
- EPSS 0.26%
- Veröffentlicht 23.11.2022 15:15:10
- Zuletzt bearbeitet 25.04.2025 20:15:36
A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafted link that executes an arbitr...
CVE-2022-45151
- EPSS 0.25%
- Veröffentlicht 23.11.2022 15:15:10
- Zuletzt bearbeitet 25.04.2025 20:15:36
The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser i...
CVE-2022-3500
- EPSS 0.03%
- Veröffentlicht 22.11.2022 19:15:17
- Zuletzt bearbeitet 29.04.2025 05:15:43
A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts ...
CVE-2022-36227
- EPSS 0.46%
- Veröffentlicht 22.11.2022 02:15:11
- Zuletzt bearbeitet 21.11.2024 07:12:37
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476...
CVE-2021-33621
- EPSS 2.3%
- Veröffentlicht 18.11.2022 23:15:18
- Zuletzt bearbeitet 21.11.2024 06:09:12
The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.
CVE-2022-39317
- EPSS 0.06%
- Veröffentlicht 16.11.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:18:01
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check for input offset index in ZGFX decoder. A malicious server can trick a FreeRDP based client to read out of bound data and try to dec...
CVE-2022-39318
- EPSS 0.11%
- Veröffentlicht 16.11.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:18:01
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input validation in `urbdrc` channel. A malicious server can trick a FreeRDP based client to crash with division by zero. This issue has been addr...