CVE-2022-0519
- EPSS 0.36%
- Veröffentlicht 08.02.2022 21:15:19
- Zuletzt bearbeitet 21.11.2024 06:38:49
Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2.
CVE-2022-0520
- EPSS 0.33%
- Veröffentlicht 08.02.2022 21:15:19
- Zuletzt bearbeitet 21.11.2024 06:38:49
Use After Free in NPM radare2.js prior to 5.6.2.
CVE-2022-0521
- EPSS 0.36%
- Veröffentlicht 08.02.2022 21:15:19
- Zuletzt bearbeitet 21.11.2024 06:38:49
Access of Memory Location After End of Buffer in GitHub repository radareorg/radare2 prior to 5.6.2.
CVE-2022-21702
- EPSS 1.25%
- Veröffentlicht 08.02.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:45:16
Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a specially crafted link and exe...
CVE-2022-21712
- EPSS 0.21%
- Veröffentlicht 07.02.2022 22:15:08
- Zuletzt bearbeitet 25.11.2024 18:12:24
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. Br...
CVE-2022-23613
- EPSS 0.38%
- Veröffentlicht 07.02.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:48:56
xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code...
CVE-2021-41816
- EPSS 0.91%
- Veröffentlicht 06.02.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:26:48
CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This also affects the CGI gem befo...
CVE-2022-23614
- EPSS 45.72%
- Veröffentlicht 04.02.2022 23:15:15
- Zuletzt bearbeitet 21.11.2024 06:48:56
Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly...
CVE-2022-23946
- EPSS 0.75%
- Veröffentlicht 04.02.2022 23:15:15
- Zuletzt bearbeitet 21.11.2024 06:49:30
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An ...
CVE-2022-23947
- EPSS 0.55%
- Veröffentlicht 04.02.2022 23:15:15
- Zuletzt bearbeitet 21.11.2024 06:49:30
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An ...