CVE-2022-24724
- EPSS 4.19%
- Published 03.03.2022 20:15:07
- Last modified 21.11.2024 06:50:57
cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark. Prior to versions 0.29.0.gfm.3 and 0.28.3.gfm.21, an integer overflow in cmark-gfm's table row parsing `table.c:row_from_string` may lead to heap memory corruptio...
CVE-2022-0492
- EPSS 5.8%
- Published 03.03.2022 19:15:08
- Last modified 21.11.2024 06:38:46
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the...
CVE-2022-26126
- EPSS 0.08%
- Published 03.03.2022 18:15:08
- Last modified 04.11.2025 16:15:48
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c.
CVE-2022-23648
- EPSS 6.3%
- Published 03.03.2022 14:15:07
- Last modified 21.11.2024 06:49:00
containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-craf...
CVE-2021-3623
- EPSS 0.04%
- Published 02.03.2022 23:15:08
- Last modified 21.11.2024 06:22:00
A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal values and may lead to an out-of-bounds access when the volatile state of the TPM 2 is marshalled/written or unmarshalled/read. The h...
CVE-2021-3658
- EPSS 0.06%
- Published 02.03.2022 23:15:08
- Last modified 04.11.2025 16:15:43
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to in...
CVE-2021-3677
- EPSS 0.19%
- Published 02.03.2022 23:15:08
- Last modified 21.11.2024 06:22:08
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objec...
CVE-2022-23308
- EPSS 0.05%
- Published 26.02.2022 05:15:08
- Last modified 05.05.2025 17:17:56
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
CVE-2021-26252
- EPSS 0.39%
- Published 24.02.2022 19:15:09
- Last modified 21.11.2024 05:55:59
A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service.
CVE-2021-3596
- EPSS 0.17%
- Published 24.02.2022 19:15:09
- Last modified 21.11.2024 06:21:55
A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which ...