CVE-2022-3234
- EPSS 0.05%
- Veröffentlicht 17.09.2022 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:19:06
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.
CVE-2022-30674
- EPSS 0.15%
- Veröffentlicht 16.09.2022 18:15:12
- Zuletzt bearbeitet 21.11.2024 07:03:08
Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASL...
CVE-2022-39209
- EPSS 1.1%
- Veröffentlicht 15.09.2022 18:15:12
- Zuletzt bearbeitet 21.11.2024 07:17:47
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and sub...
CVE-2022-40674
- EPSS 0.91%
- Veröffentlicht 14.09.2022 11:15:54
- Zuletzt bearbeitet 30.05.2025 20:15:30
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
CVE-2022-40626
- EPSS 1.87%
- Veröffentlicht 14.09.2022 11:15:53
- Zuletzt bearbeitet 21.11.2024 07:21:44
An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in Zabbix Frontend.
CVE-2022-40673
- EPSS 0.08%
- Veröffentlicht 14.09.2022 11:15:53
- Zuletzt bearbeitet 21.11.2024 07:21:49
KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache.
CVE-2021-36568
- EPSS 0.41%
- Veröffentlicht 13.09.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:13:50
In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting S...
CVE-2022-38013
- EPSS 1%
- Veröffentlicht 13.09.2022 19:15:12
- Zuletzt bearbeitet 02.01.2025 20:15:59
.NET Core and Visual Studio Denial of Service Vulnerability
CVE-2022-3190
- EPSS 0.02%
- Veröffentlicht 13.09.2022 15:15:09
- Zuletzt bearbeitet 03.11.2025 22:15:59
Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0 to 3.4.15 allows denial of service via packet injection or crafted capture file
CVE-2022-36087
- EPSS 0.31%
- Veröffentlicht 09.09.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:12:21
OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious redirect uri can cause denial of service. An attacker can also leverage usage of `uri_validate` ...