CVE-2022-0238
- EPSS 0.17%
 - Published 16.01.2022 11:15:07
 - Last modified 21.11.2024 06:38:12
 
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-44537
- EPSS 1.09%
 - Published 15.01.2022 21:15:09
 - Last modified 21.11.2024 06:31:11
 
ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution.
CVE-2022-23094
- EPSS 1.3%
 - Published 15.01.2022 02:15:06
 - Last modified 21.11.2024 06:47:58
 
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.
CVE-2021-46019
- EPSS 0.2%
 - Published 14.01.2022 20:15:15
 - Last modified 21.11.2024 06:33:28
 
An untrusted pointer dereference in rec_db_destroy() at rec-db.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
CVE-2021-46021
- EPSS 0.13%
 - Published 14.01.2022 20:15:15
 - Last modified 21.11.2024 06:33:29
 
An Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
CVE-2021-46022
- EPSS 0.19%
 - Published 14.01.2022 20:15:15
 - Last modified 21.11.2024 06:33:29
 
An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
CVE-2022-21680
- EPSS 0.49%
 - Published 14.01.2022 17:15:13
 - Last modified 21.11.2024 06:45:13
 
Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). Anyone who runs untrusted markd...
CVE-2022-21681
- EPSS 0.7%
 - Published 14.01.2022 17:15:13
 - Last modified 21.11.2024 06:45:13
 
Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.reflinkSearch` may cause catastrophic backtracking against some strings and lead to a denial of service (DoS). Anyone who runs untrusted markdown throug...
CVE-2022-23222
- EPSS 0.73%
 - Published 14.01.2022 08:15:07
 - Last modified 21.11.2024 06:48:13
 
kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.
CVE-2022-21682
- EPSS 0.36%
 - Published 13.01.2022 21:15:08
 - Last modified 21.11.2024 06:45:13
 
Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies `finish-args` last in the build. At this point the build directory wi...