CVE-2022-29824
- EPSS 0.07%
- Veröffentlicht 03.05.2022 03:15:06
- Zuletzt bearbeitet 21.11.2024 06:59:45
In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte...
CVE-2021-46790
- EPSS 0.04%
- Veröffentlicht 02.05.2022 12:16:26
- Zuletzt bearbeitet 21.11.2024 06:34:43
ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.
CVE-2022-29968
- EPSS 1.78%
- Veröffentlicht 02.05.2022 04:15:10
- Zuletzt bearbeitet 21.11.2024 07:00:05
An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private.
CVE-2022-25844
- EPSS 1.92%
- Veröffentlicht 01.05.2022 16:15:08
- Zuletzt bearbeitet 20.11.2025 17:53:57
The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very h...
CVE-2022-0984
- EPSS 0.26%
- Veröffentlicht 29.04.2022 17:15:20
- Zuletzt bearbeitet 21.11.2024 06:39:47
Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.
CVE-2022-1015
- EPSS 1.48%
- Veröffentlicht 29.04.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:39:51
A flaw was found in the Linux kernel in linux/net/netfilter/nf_tables_api.c of the netfilter subsystem. This flaw allows a local user to cause an out-of-bounds write issue.
CVE-2022-1227
- EPSS 32.06%
- Veröffentlicht 29.04.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:40:17
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' co...
CVE-2022-29869
- EPSS 1.25%
- Veröffentlicht 28.04.2022 01:15:06
- Zuletzt bearbeitet 21.11.2024 06:59:51
cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.
CVE-2022-24735
- EPSS 1.73%
- Veröffentlicht 27.04.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:50:58
Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will execute with the (potentially highe...
CVE-2022-24736
- EPSS 0.97%
- Veröffentlicht 27.04.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:50:58
Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The ...