CVE-2022-41032
- EPSS 14.65%
- Veröffentlicht 11.10.2022 19:15:20
- Zuletzt bearbeitet 28.02.2025 21:15:18
NuGet Client Elevation of Privilege Vulnerability
CVE-2022-33746
- EPSS 0.03%
- Veröffentlicht 11.10.2022 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:08:27
P2M pool freeing may take excessively long The P2M pool backing second level address translation for guests may be of significant size. Therefore its freeing may take more time than is reasonable without intermediate preemption checks. Such checking ...
CVE-2022-33747
- EPSS 0.02%
- Veröffentlicht 11.10.2022 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:08:27
Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing pages from a guest's P2M (Physical-to-Machine) mapping. When large pages are in use to map guest pages in the 2nd-stage page tables, such a removal oper...
CVE-2022-33748
- EPSS 0.03%
- Veröffentlicht 11.10.2022 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:08:27
lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanup call was inserted on an error handling path. While doing so, locking requirements were not paid attention to. As a result two cooperating guests granting each...
CVE-2022-42010
- EPSS 0.05%
- Veröffentlicht 10.10.2022 00:15:09
- Zuletzt bearbeitet 09.06.2025 15:15:27
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid typ...
CVE-2022-42011
- EPSS 0.09%
- Veröffentlicht 10.10.2022 00:15:09
- Zuletzt bearbeitet 09.06.2025 15:15:28
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is...
CVE-2022-42012
- EPSS 0.09%
- Veröffentlicht 10.10.2022 00:15:09
- Zuletzt bearbeitet 09.06.2025 15:15:28
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descripto...
CVE-2022-3435
- EPSS 0.08%
- Veröffentlicht 08.10.2022 11:15:10
- Zuletzt bearbeitet 21.11.2024 07:19:30
A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the file net/ipv4/fib_semantics.c of the component IPv4 Handler. The manipulation leads to out-of-bounds read. It is possible to initi...
CVE-2022-3275
- EPSS 0.85%
- Veröffentlicht 07.10.2022 21:15:11
- Zuletzt bearbeitet 21.11.2024 07:19:11
Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of...
CVE-2022-2929
- EPSS 0.04%
- Veröffentlicht 07.10.2022 05:15:11
- Zuletzt bearbeitet 21.11.2024 07:01:56
In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run out of memory.