CVE-2022-1328
- EPSS 0.17%
- Published 14.04.2022 21:15:08
- Last modified 21.11.2024 06:40:29
Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line
CVE-2022-24828
- EPSS 0.22%
- Published 13.04.2022 21:15:07
- Last modified 21.11.2024 06:51:11
Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a code injection vulnerability if the user can control the `$file` or `$identifier` argument. This leads t...
- EPSS 0.8%
- Published 13.04.2022 16:15:08
- Last modified 03.11.2025 22:15:43
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untruste...
CVE-2022-24070
- EPSS 0.56%
- Published 12.04.2022 18:15:09
- Last modified 21.11.2024 06:49:45
Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (i...
CVE-2022-24765
- EPSS 0.2%
- Published 12.04.2022 18:15:09
- Last modified 21.11.2024 06:51:02
Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C...
CVE-2021-28544
- EPSS 0.29%
- Published 12.04.2022 18:15:08
- Last modified 21.11.2024 05:59:49
Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, us...
CVE-2022-24836
- EPSS 1.5%
- Published 11.04.2022 22:15:07
- Last modified 21.11.2024 06:51:12
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade...
CVE-2022-28805
- EPSS 0.17%
- Published 08.04.2022 06:15:07
- Last modified 21.11.2024 06:57:57
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
- EPSS 0.1%
- Published 08.04.2022 05:15:07
- Last modified 21.11.2024 06:57:57
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
CVE-2021-43138
- EPSS 0.71%
- Published 06.04.2022 17:15:08
- Last modified 21.11.2024 06:28:43
In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.