CVE-2022-45151
- EPSS 0.33%
- Veröffentlicht 23.11.2022 15:15:10
- Zuletzt bearbeitet 25.04.2025 20:15:36
The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser i...
CVE-2022-3500
- EPSS 0.04%
- Veröffentlicht 22.11.2022 19:15:17
- Zuletzt bearbeitet 29.04.2025 05:15:43
A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts ...
CVE-2022-36227
- EPSS 0.42%
- Veröffentlicht 22.11.2022 02:15:11
- Zuletzt bearbeitet 03.11.2025 22:15:59
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476...
CVE-2021-33621
- EPSS 1.52%
- Veröffentlicht 18.11.2022 23:15:18
- Zuletzt bearbeitet 04.11.2025 16:15:42
The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.
CVE-2022-39317
- EPSS 0.07%
- Veröffentlicht 16.11.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:18:01
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check for input offset index in ZGFX decoder. A malicious server can trick a FreeRDP based client to read out of bound data and try to dec...
CVE-2022-39318
- EPSS 0.14%
- Veröffentlicht 16.11.2022 21:15:10
- Zuletzt bearbeitet 03.11.2025 21:15:53
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input validation in `urbdrc` channel. A malicious server can trick a FreeRDP based client to crash with division by zero. This issue has been addr...
CVE-2022-39319
- EPSS 0.1%
- Veröffentlicht 16.11.2022 21:15:10
- Zuletzt bearbeitet 03.11.2025 21:15:53
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in the `urbdrc` channel. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to...
CVE-2022-39316
- EPSS 0.14%
- Veröffentlicht 16.11.2022 20:15:10
- Zuletzt bearbeitet 03.11.2025 21:15:52
FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRDP. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it...
CVE-2022-39320
- EPSS 0.06%
- Veröffentlicht 16.11.2022 20:15:10
- Zuletzt bearbeitet 03.11.2025 21:15:53
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP may attempt integer addition on too narrow types leads to allocation of a buffer too small holding the data written. A malicious server can trick a FreeRDP ba...
CVE-2022-39347
- EPSS 0.14%
- Veröffentlicht 16.11.2022 20:15:10
- Zuletzt bearbeitet 03.11.2025 21:15:53
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for `drive` channel. A malicious server can trick a FreeRDP based client to read files outside the share...