Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26 087

Количество 26 087

msrc логотип

CVE-2022-4515

больше 3 лет назад

A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-45142

больше 1 года назад

The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-45141

почти 2 года назад

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2022-45063

больше 3 лет назад

xterm before 375 allows code execution via font ops e.g. because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2022-45061

больше 3 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-44793

почти 4 года назад

CVSS3: 6.5
EPSS: Средний
msrc логотип

CVE-2022-44792

почти 4 года назад

CVSS3: 6.5
EPSS: Средний
msrc логотип

CVE-2022-44713

больше 3 лет назад

Microsoft Outlook for Mac Spoofing Vulnerability

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-44710

больше 3 лет назад

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-44708

больше 3 лет назад

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVSS3: 8.3
EPSS: Низкий
msrc логотип

CVE-2022-44707

больше 3 лет назад

Windows Kernel Denial of Service Vulnerability

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2022-44704

больше 3 лет назад

Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-44702

больше 3 лет назад

Windows Terminal Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-44699

больше 3 лет назад

Azure Network Watcher Agent Security Feature Bypass Vulnerability

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2022-44698

больше 3 лет назад

Windows SmartScreen Security Feature Bypass Vulnerability

CVSS3: 5.4
EPSS: Высокий
msrc логотип

CVE-2022-44697

больше 3 лет назад

Windows Graphics Component Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-44696

больше 3 лет назад

Microsoft Office Visio Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-44695

больше 3 лет назад

Microsoft Office Visio Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-44694

больше 3 лет назад

Microsoft Office Visio Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-44693

больше 3 лет назад

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2022-4515

A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-45142

The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 9.8
0%
Низкий
почти 2 года назад
msrc логотип
CVE-2022-45063

xterm before 375 allows code execution via font ops e.g. because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.

CVSS3: 9.8
5%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 7.5
2%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 6.5
53%
Средний
почти 4 года назад
msrc логотип
CVSS3: 6.5
52%
Средний
почти 4 года назад
msrc логотип
CVE-2022-44713

Microsoft Outlook for Mac Spoofing Vulnerability

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-44710

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-44708

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVSS3: 8.3
2%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-44707

Windows Kernel Denial of Service Vulnerability

CVSS3: 6.5
3%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-44704

Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-44702

Windows Terminal Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-44699

Azure Network Watcher Agent Security Feature Bypass Vulnerability

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-44698

Windows SmartScreen Security Feature Bypass Vulnerability

CVSS3: 5.4
76%
Высокий
больше 3 лет назад
msrc логотип
CVE-2022-44697

Windows Graphics Component Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-44696

Microsoft Office Visio Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-44695

Microsoft Office Visio Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-44694

Microsoft Office Visio Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-44693

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVSS3: 8.8
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу