Количество 26 087
Количество 26 087
CVE-2022-4515
A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.
CVE-2022-45142
The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted.
CVE-2022-45141
CVE-2022-45063
xterm before 375 allows code execution via font ops e.g. because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.
CVE-2022-45061
CVE-2022-44793
CVE-2022-44792
CVE-2022-44713
Microsoft Outlook for Mac Spoofing Vulnerability
CVE-2022-44710
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2022-44708
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2022-44707
Windows Kernel Denial of Service Vulnerability
CVE-2022-44704
Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability
CVE-2022-44702
Windows Terminal Remote Code Execution Vulnerability
CVE-2022-44699
Azure Network Watcher Agent Security Feature Bypass Vulnerability
CVE-2022-44698
Windows SmartScreen Security Feature Bypass Vulnerability
CVE-2022-44697
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2022-44696
Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2022-44695
Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2022-44694
Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2022-44693
Microsoft SharePoint Server Remote Code Execution Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-4515 A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way. | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
CVE-2022-45142 The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported to the heimdal-7.7.1 and heimdal-7.8.0 branches (and possibly other branches) a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
CVSS3: 9.8 | 0% Низкий | почти 2 года назад | ||
CVE-2022-45063 xterm before 375 allows code execution via font ops e.g. because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions. | CVSS3: 9.8 | 5% Низкий | больше 3 лет назад | |
CVSS3: 7.5 | 2% Низкий | больше 3 лет назад | ||
CVSS3: 6.5 | 53% Средний | почти 4 года назад | ||
CVSS3: 6.5 | 52% Средний | почти 4 года назад | ||
CVE-2022-44713 Microsoft Outlook for Mac Spoofing Vulnerability | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
CVE-2022-44710 DirectX Graphics Kernel Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
CVE-2022-44708 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | CVSS3: 8.3 | 2% Низкий | больше 3 лет назад | |
CVE-2022-44707 Windows Kernel Denial of Service Vulnerability | CVSS3: 6.5 | 3% Низкий | больше 3 лет назад | |
CVE-2022-44704 Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
CVE-2022-44702 Windows Terminal Remote Code Execution Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
CVE-2022-44699 Azure Network Watcher Agent Security Feature Bypass Vulnerability | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
CVE-2022-44698 Windows SmartScreen Security Feature Bypass Vulnerability | CVSS3: 5.4 | 76% Высокий | больше 3 лет назад | |
CVE-2022-44697 Windows Graphics Component Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
CVE-2022-44696 Microsoft Office Visio Remote Code Execution Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
CVE-2022-44695 Microsoft Office Visio Remote Code Execution Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
CVE-2022-44694 Microsoft Office Visio Remote Code Execution Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
CVE-2022-44693 Microsoft SharePoint Server Remote Code Execution Vulnerability | CVSS3: 8.8 | 2% Низкий | больше 3 лет назад |
Уязвимостей на страницу