CVE-2022-1328
- EPSS 0.17%
- Veröffentlicht 14.04.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:40:29
Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line
CVE-2022-24828
- EPSS 0.22%
- Veröffentlicht 13.04.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:11
Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a code injection vulnerability if the user can control the `$file` or `$identifier` argument. This leads t...
- EPSS 0.8%
- Veröffentlicht 13.04.2022 16:15:08
- Zuletzt bearbeitet 03.11.2025 22:15:43
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untruste...
CVE-2022-24070
- EPSS 0.56%
- Veröffentlicht 12.04.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:49:45
Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (i...
CVE-2022-24765
- EPSS 0.2%
- Veröffentlicht 12.04.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:51:02
Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C...
CVE-2021-28544
- EPSS 0.29%
- Veröffentlicht 12.04.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:59:49
Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, us...
CVE-2022-24836
- EPSS 1.5%
- Veröffentlicht 11.04.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:12
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade...
CVE-2022-28805
- EPSS 0.17%
- Veröffentlicht 08.04.2022 06:15:07
- Zuletzt bearbeitet 21.11.2024 06:57:57
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
- EPSS 0.1%
- Veröffentlicht 08.04.2022 05:15:07
- Zuletzt bearbeitet 21.11.2024 06:57:57
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
CVE-2021-43138
- EPSS 0.71%
- Veröffentlicht 06.04.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:28:43
In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.