CVE-2022-2611
- EPSS 0.36%
- Veröffentlicht 12.08.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 07:01:21
Inappropriate implementation in Fullscreen API in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2022-2612
- EPSS 0.39%
- Veröffentlicht 12.08.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 07:01:21
Side-channel information leakage in Keyboard input in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page.
CVE-2022-38150
- EPSS 0.71%
- Veröffentlicht 11.08.2022 01:15:10
- Zuletzt bearbeitet 20.10.2025 18:15:37
In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This ...
CVE-2022-2719
- EPSS 0.02%
- Veröffentlicht 10.08.2022 20:15:36
- Zuletzt bearbeitet 21.11.2024 07:01:34
In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMagick versio...
CVE-2022-28131
- EPSS 0.01%
- Veröffentlicht 10.08.2022 20:15:32
- Zuletzt bearbeitet 21.11.2024 06:56:48
Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.
CVE-2021-33643
- EPSS 0.19%
- Veröffentlicht 10.08.2022 20:15:20
- Zuletzt bearbeitet 03.11.2025 21:15:41
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read.
CVE-2021-33644
- EPSS 0.19%
- Veröffentlicht 10.08.2022 20:15:20
- Zuletzt bearbeitet 03.11.2025 21:15:41
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longname, causing an out-of-bounds read.
CVE-2021-33645
- EPSS 0.18%
- Veröffentlicht 10.08.2022 20:15:20
- Zuletzt bearbeitet 03.11.2025 21:15:41
The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.
CVE-2021-33646
- EPSS 0.18%
- Veröffentlicht 10.08.2022 20:15:20
- Zuletzt bearbeitet 03.11.2025 21:15:41
The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.
CVE-2021-37150
- EPSS 0.26%
- Veröffentlicht 10.08.2022 06:15:08
- Zuletzt bearbeitet 08.09.2025 19:15:31
Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.