CVE-2022-24765
- EPSS 0.18%
- Veröffentlicht 12.04.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:51:02
Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C...
CVE-2021-28544
- EPSS 0.38%
- Veröffentlicht 12.04.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:59:49
Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, us...
CVE-2022-24836
- EPSS 1.45%
- Veröffentlicht 11.04.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:12
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade...
CVE-2022-28805
- EPSS 0.17%
- Veröffentlicht 08.04.2022 06:15:07
- Zuletzt bearbeitet 21.11.2024 06:57:57
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
- EPSS 0.1%
- Veröffentlicht 08.04.2022 05:15:07
- Zuletzt bearbeitet 21.11.2024 06:57:57
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
CVE-2021-43138
- EPSS 0.71%
- Veröffentlicht 06.04.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:28:43
In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.
CVE-2022-26356
- EPSS 0.03%
- Veröffentlicht 05.04.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:53:49
Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was named HVMOP_track_dirty_vram before Xen 4.9) is racy with ongoing log dirty hypercalls. A suitably timed...
- EPSS 0.01%
- Veröffentlicht 05.04.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:53:49
race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associating a physical device with a particular domain. Therefore internally Xen domain IDs are mapped to the...
CVE-2022-26358
- EPSS 0.09%
- Veröffentlicht 05.04.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:53:49
IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memo...
CVE-2022-26359
- EPSS 0.09%
- Veröffentlicht 05.04.2022 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:53:49
IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memo...