CVE-2022-38177
- EPSS 1.32%
- Veröffentlicht 21.09.2022 11:15:09
- Zuletzt bearbeitet 28.05.2025 16:15:26
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
CVE-2022-38178
- EPSS 1.48%
- Veröffentlicht 21.09.2022 11:15:09
- Zuletzt bearbeitet 28.05.2025 16:15:26
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
CVE-2022-3080
- EPSS 0.07%
- Veröffentlicht 21.09.2022 11:15:09
- Zuletzt bearbeitet 21.11.2024 07:18:46
By sending specific queries to the resolver, an attacker can cause named to crash.
CVE-2022-35957
- EPSS 0.87%
- Veröffentlicht 20.09.2022 23:15:09
- Zuletzt bearbeitet 21.11.2024 07:12:03
Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over the server admin account and ga...
CVE-2022-32886
- EPSS 0.67%
- Veröffentlicht 20.09.2022 21:15:11
- Zuletzt bearbeitet 29.05.2025 15:15:21
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution.
CVE-2022-39955
- EPSS 0.13%
- Veröffentlicht 20.09.2022 07:15:12
- Zuletzt bearbeitet 03.11.2025 20:15:56
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field that indicates multiple character encoding schemes. A vulnerable back-end can potentially be exploited...
CVE-2022-39956
- EPSS 0.09%
- Veröffentlicht 20.09.2022 07:15:12
- Zuletzt bearbeitet 03.11.2025 20:15:56
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MI...
CVE-2022-39957
- EPSS 0.12%
- Veröffentlicht 20.09.2022 07:15:12
- Zuletzt bearbeitet 03.11.2025 20:15:56
The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded form. Depending on the "charset"...
CVE-2022-39958
- EPSS 0.22%
- Veröffentlicht 20.09.2022 07:15:12
- Zuletzt bearbeitet 03.11.2025 20:15:56
The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by repeatedly submitting an HTTP Range header field with a small byte range. A restricted resource, acc...
CVE-2022-3213
- EPSS 0.03%
- Veröffentlicht 19.09.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 07:19:03
A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service.