CVE-2022-27191
- EPSS 0.09%
- Veröffentlicht 18.03.2022 07:15:06
- Zuletzt bearbeitet 21.11.2024 06:55:22
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
CVE-2022-24302
- EPSS 0.54%
- Veröffentlicht 17.03.2022 22:15:08
- Zuletzt bearbeitet 16.12.2025 02:15:46
In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
CVE-2022-24729
- EPSS 0.51%
- Veröffentlicht 16.03.2022 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:50:57
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a ...
CVE-2021-23648
- EPSS 0.12%
- Veröffentlicht 16.03.2022 16:15:10
- Zuletzt bearbeitet 21.11.2024 05:51:51
The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
CVE-2022-24728
- EPSS 0.72%
- Veröffentlicht 16.03.2022 16:15:10
- Zuletzt bearbeitet 21.11.2024 06:50:57
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to in...
CVE-2021-20257
- EPSS 0.08%
- Veröffentlicht 16.03.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 05:46:13
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. This flaw allows a guest to cons...
CVE-2021-45848
- EPSS 0.48%
- Veröffentlicht 15.03.2022 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:33:09
Denial of service (DoS) vulnerability in Nicotine+ 3.0.3 and later allows a user with a modified Soulseek client to crash Nicotine+ by sending a file download request with a file path containing a null character.
CVE-2022-0778
- EPSS 7.19%
- Veröffentlicht 15.03.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:39:22
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed ...
CVE-2022-0943
- EPSS 0.06%
- Veröffentlicht 14.03.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:39:42
Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563.
CVE-2022-20001
- EPSS 0.41%
- Veröffentlicht 14.03.2022 19:15:11
- Zuletzt bearbeitet 21.11.2024 06:41:55
fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-repository configuration that change the behavior of git, including running arbitrary commands. When us...