CVE-2022-20796
- EPSS 0.03%
- Published 04.05.2022 17:15:08
- Last modified 21.11.2024 06:43:34
On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in Clam AntiVirus (ClamAV) versions 0.103.4, 0.103.5, 0.104.1, and 0.104.2 could allow an a...
CVE-2022-28487
- EPSS 0.47%
- Published 04.05.2022 15:15:12
- Last modified 21.11.2024 06:57:25
Tcpreplay version 4.4.1 contains a memory leakage flaw in fix_ipv6_checksums() function. The highest threat from this vulnerability is to data confidentiality.
CVE-2022-27470
- EPSS 0.15%
- Published 04.05.2022 03:15:07
- Last modified 21.11.2024 06:55:47
SDL_ttf v2.0.18 and below was discovered to contain an arbitrary memory write via the function TTF_RenderText_Solid(). This vulnerability is triggered via a crafted TTF file.
- EPSS 47.77%
- Published 03.05.2022 16:15:18
- Last modified 13.08.2025 14:15:28
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execut...
CVE-2022-29824
- EPSS 0.07%
- Published 03.05.2022 03:15:06
- Last modified 21.11.2024 06:59:45
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte...
CVE-2021-46790
- EPSS 0.04%
- Published 02.05.2022 12:16:26
- Last modified 21.11.2024 06:34:43
ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.
CVE-2022-29968
- EPSS 1.78%
- Published 02.05.2022 04:15:10
- Last modified 21.11.2024 07:00:05
An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private.
CVE-2022-25844
- EPSS 1.61%
- Published 01.05.2022 16:15:08
- Last modified 03.11.2025 20:15:53
The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very h...
CVE-2022-0984
- EPSS 0.26%
- Published 29.04.2022 17:15:20
- Last modified 21.11.2024 06:39:47
Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.
CVE-2022-1015
- EPSS 1.89%
- Published 29.04.2022 16:15:08
- Last modified 21.11.2024 06:39:51
A flaw was found in the Linux kernel in linux/net/netfilter/nf_tables_api.c of the netfilter subsystem. This flaw allows a local user to cause an out-of-bounds write issue.