CVE-2022-24713
- EPSS 5.11%
- Veröffentlicht 08.03.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:50:55
regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mi...
CVE-2022-24737
- EPSS 0.6%
- Veröffentlicht 07.03.2022 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:50:59
HTTPie is a command-line HTTP client. HTTPie has the practical concept of sessions, which help users to persistently store some of the state that belongs to the outgoing requests and incoming responses on the disk for further usage. Before 3.1.0, HTT...
CVE-2022-26495
- EPSS 0.29%
- Veröffentlicht 06.03.2022 06:15:07
- Zuletzt bearbeitet 21.11.2024 06:54:03
In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resulting in a write to a dangling...
CVE-2022-26496
- EPSS 0.42%
- Veröffentlicht 06.03.2022 06:15:07
- Zuletzt bearbeitet 21.11.2024 06:54:03
In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by sending a crafted NBD_OPT_INFO or NBD_OPT_GO message with an large value as the length of the name.
CVE-2022-26490
- EPSS 0.03%
- Veröffentlicht 06.03.2022 04:15:07
- Zuletzt bearbeitet 25.06.2025 21:01:34
st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.
CVE-2021-3656
- EPSS 0.07%
- Veröffentlicht 04.03.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:05
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the ...
CVE-2021-3737
- EPSS 0.25%
- Veröffentlicht 04.03.2022 19:15:08
- Zuletzt bearbeitet 17.12.2025 22:15:56
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from...
CVE-2021-3575
- EPSS 0.3%
- Veröffentlicht 04.03.2022 18:15:08
- Zuletzt bearbeitet 03.11.2025 20:15:50
A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg.
CVE-2021-23214
- EPSS 0.36%
- Veröffentlicht 04.03.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:23
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certif...
CVE-2021-3743
- EPSS 0.01%
- Veröffentlicht 04.03.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:18
An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux kernel. A missing sanity check allows a local attacker to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel i...