CVE-2022-28390
- EPSS 0.01%
- Veröffentlicht 03.04.2022 21:15:08
- Zuletzt bearbeitet 25.06.2025 21:00:27
ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.
CVE-2021-3847
- EPSS 0.04%
- Veröffentlicht 01.04.2022 23:15:10
- Zuletzt bearbeitet 21.11.2024 06:22:38
An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to esc...
CVE-2022-24790
- EPSS 0.39%
- Veröffentlicht 30.03.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:06
Puma is a simple, fast, multi-threaded, parallel HTTP 1.1 server for Ruby/Rack applications. When using Puma behind a proxy that does not properly validate that the incoming HTTP request matches the RFC7230 standard, Puma and the frontend proxy may d...
CVE-2022-1160
- EPSS 0.14%
- Veröffentlicht 30.03.2022 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:40:09
heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.
CVE-2022-1154
- EPSS 0.6%
- Veröffentlicht 30.03.2022 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:40:08
Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.
CVE-2022-28202
- EPSS 0.4%
- Veröffentlicht 30.03.2022 06:15:06
- Zuletzt bearbeitet 21.11.2024 06:56:56
An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete.
CVE-2022-1122
- EPSS 0.05%
- Veröffentlicht 29.03.2022 18:15:07
- Zuletzt bearbeitet 03.11.2025 20:15:52
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitia...
CVE-2022-1055
- EPSS 0.03%
- Veröffentlicht 29.03.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:39:56
A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4...
CVE-2022-26280
- EPSS 0.16%
- Veröffentlicht 28.03.2022 22:15:09
- Zuletzt bearbeitet 03.11.2025 22:15:57
Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.
CVE-2022-24303
- EPSS 1.38%
- Veröffentlicht 28.03.2022 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:50:07
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.