CVE-2022-0110
- EPSS 0.46%
- Veröffentlicht 12.02.2022 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:37:55
Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2022-0111
- EPSS 0.2%
- Veröffentlicht 12.02.2022 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:37:55
Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to incorrectly set origin via a crafted HTML page.
CVE-2022-0112
- EPSS 0.51%
- Veröffentlicht 12.02.2022 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:37:55
Incorrect security UI in Browser UI in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to display missing URL or incorrect URL via a crafted URL.
CVE-2022-0113
- EPSS 0.29%
- Veröffentlicht 12.02.2022 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:37:56
Inappropriate implementation in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2022-0114
- EPSS 0.61%
- Veröffentlicht 12.02.2022 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:37:56
Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page and virtual serial port driver.
CVE-2022-0115
- EPSS 0.53%
- Veröffentlicht 12.02.2022 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:37:56
Uninitialized use in File API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVE-2022-23634
- EPSS 0.48%
- Veröffentlicht 11.02.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:48:58
Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5.6.2`, `puma` may not always call `close` on the response body. Rails, prior to version `7.0.2.2`, depended on the response body being closed in order for its `CurrentAtt...
CVE-2022-0561
- EPSS 0.06%
- Veröffentlicht 11.02.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:38:55
Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, t...
CVE-2022-0562
- EPSS 0.03%
- Veröffentlicht 11.02.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:38:55
Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, a fix...
CVE-2022-24958
- EPSS 0.05%
- Veröffentlicht 11.02.2022 06:15:06
- Zuletzt bearbeitet 21.11.2024 06:51:27
drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.