CVE-2022-42799
- EPSS 0.46%
- Veröffentlicht 01.11.2022 20:15:22
- Zuletzt bearbeitet 05.05.2025 17:18:18
The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Visiting a malicious website may lead to user interface spoofing.
CVE-2022-3786
- EPSS 20.63%
- Veröffentlicht 01.11.2022 18:15:11
- Zuletzt bearbeitet 04.11.2025 20:16:04
A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed a malicious certificate or for...
CVE-2022-3602
- EPSS 83.22%
- Veröffentlicht 01.11.2022 18:15:10
- Zuletzt bearbeitet 04.11.2025 20:16:04
A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or f...
- EPSS 0.8%
- Veröffentlicht 01.11.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 07:18:09
phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate tickets. This allows a...
CVE-2022-42324
- EPSS 0.03%
- Veröffentlicht 01.11.2022 13:15:12
- Zuletzt bearbeitet 21.11.2024 07:24:45
Oxenstored 32->31 bit integer truncation issues Integers in Ocaml are 63 or 31 bits of signed precision. The Ocaml Xenbus library takes a C uint32_t out of the ring and casts it directly to an Ocaml integer. In 64-bit Ocaml builds this is fine, but i...
CVE-2022-42325
- EPSS 0.03%
- Veröffentlicht 01.11.2022 13:15:12
- Zuletzt bearbeitet 21.11.2024 07:24:45
Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] In case a node has been created in a transaction a...
CVE-2022-42326
- EPSS 0.03%
- Veröffentlicht 01.11.2022 13:15:12
- Zuletzt bearbeitet 05.05.2025 16:15:20
Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] In case a node has been created in a transaction a...
CVE-2022-42327
- EPSS 0.01%
- Veröffentlicht 01.11.2022 13:15:12
- Zuletzt bearbeitet 05.05.2025 20:15:18
x86: unintended memory sharing between guests On Intel systems that support the "virtualize APIC accesses" feature, a guest can read and write the global shared xAPIC page by moving the local APIC out of xAPIC mode. Access to this shared page bypasse...
CVE-2022-42309
- EPSS 0.05%
- Veröffentlicht 01.11.2022 13:15:11
- Zuletzt bearbeitet 21.11.2024 07:24:43
Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during node creation in an error path, resulting in a crash of xenstored or a memory corruption in xenstored causing ...
CVE-2022-42310
- EPSS 0.02%
- Veröffentlicht 01.11.2022 13:15:11
- Zuletzt bearbeitet 21.11.2024 07:24:43
Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes inside a transaction resulting in an error, a malicious guest can create orphaned nodes in the Xenstore data base, as the cleanup after the error will not remove all nodes...