CVE-2022-22719
- EPSS 36.15%
- Veröffentlicht 14.03.2022 11:15:09
- Zuletzt bearbeitet 21.11.2024 06:47:18
A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.
CVE-2022-22720
- EPSS 33.37%
- Veröffentlicht 14.03.2022 11:15:09
- Zuletzt bearbeitet 21.11.2024 06:47:18
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
CVE-2022-22721
- EPSS 21.93%
- Veröffentlicht 14.03.2022 11:15:09
- Zuletzt bearbeitet 21.11.2024 06:47:19
If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.
CVE-2022-23943
- EPSS 68.55%
- Veröffentlicht 14.03.2022 11:15:09
- Zuletzt bearbeitet 01.05.2025 15:37:55
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.
CVE-2022-26981
- EPSS 0.34%
- Veröffentlicht 13.03.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:54:54
Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c).
CVE-2022-25600
- EPSS 0.14%
- Veröffentlicht 11.03.2022 18:15:40
- Zuletzt bearbeitet 07.05.2025 13:35:15
Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).
CVE-2022-25601
- EPSS 0.33%
- Veröffentlicht 11.03.2022 18:15:40
- Zuletzt bearbeitet 21.11.2024 06:52:25
Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4).
CVE-2022-0924
- EPSS 0.06%
- Veröffentlicht 11.03.2022 18:15:30
- Zuletzt bearbeitet 21.11.2024 06:39:40
Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 408976c4.
CVE-2022-0909
- EPSS 0.07%
- Veröffentlicht 11.03.2022 18:15:28
- Zuletzt bearbeitet 21.11.2024 06:39:38
Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f8d0f9aa.
CVE-2022-0908
- EPSS 0.06%
- Veröffentlicht 11.03.2022 18:15:27
- Zuletzt bearbeitet 21.11.2024 06:39:38
Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file.