Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26 087

Количество 26 087

msrc логотип

CVE-2022-42915

6 месяцев назад

curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL it sets up the connection to the remote server by issuing a CONNECT request to the proxy and then tunnels the rest of the protocol through. An HTTP proxy might refuse this request (HTTP proxies often only allow outgoing connections to specific port numbers like 443 for HTTPS) and instead return a non-200 status code to the client. Due to flaws in the error/cleanup handling this could trigger a double free in curl if one of the following schemes were used in the URL for the transfer: dict gopher gophers ldap ldaps rtmp rtmps or telnet. The earliest affected version is 7.77.0.

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2022-42898

почти 2 года назад

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2022-4285

11 месяцев назад

An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2022-42722

почти 4 года назад

In the Linux kernel 5.8 through 5.19.x before 5.19.16 local attackers able to inject WLAN frames into the mac80211 stack could cause a NULL pointer dereference denial-of-service attack against the beacon protection of P2P devices.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2022-42721

почти 4 года назад

A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked list and in turn potentially execute code.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2022-42720

почти 4 года назад

Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger use-after-free conditions to potentially execute code.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-42719

почти 4 года назад

A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before 5.19.16 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code.

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2022-42717

почти 4 года назад

An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-42703

почти 4 года назад

mm/rmap.c in the Linux kernel before 5.19.7 has a use-after-free related to leaf anon_vma double reuse.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2022-4262

больше 3 лет назад

Chromium: CVE-2022-4262 Type Confusion in V8

EPSS: Средний
msrc логотип

CVE-2022-42329

больше 3 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2022-42328

больше 3 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2022-42012

почти 4 года назад

An issue was discovered in D-Bus before 1.12.24 1.13.x and 1.14.x before 1.14.4 and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2022-42011

почти 4 года назад

An issue was discovered in D-Bus before 1.12.24 1.13.x and 1.14.x before 1.14.4 and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2022-42010

почти 4 года назад

An issue was discovered in D-Bus before 1.12.24 1.13.x and 1.14.x before 1.14.4 and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2022-41974

почти 4 года назад

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword which is mishandled because arithmetic ADD is used instead of bitwise OR.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-41973

почти 4 года назад

multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling which could lead to controlled file writes outside of the /dev/shm directory. This could be used indirectly for local privilege escalation to root.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-4195

больше 3 лет назад

Chromium: CVE-2022-4195 Insufficient policy enforcement in Safe Browsing

EPSS: Низкий
msrc логотип

CVE-2022-41953

больше 3 лет назад

Git clone remote code execution vulnerability in git-for-windows

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-4194

больше 3 лет назад

Chromium: CVE-2022-4194 Use after free in Accessibility

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2022-42915

curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL it sets up the connection to the remote server by issuing a CONNECT request to the proxy and then tunnels the rest of the protocol through. An HTTP proxy might refuse this request (HTTP proxies often only allow outgoing connections to specific port numbers like 443 for HTTPS) and instead return a non-200 status code to the client. Due to flaws in the error/cleanup handling this could trigger a double free in curl if one of the following schemes were used in the URL for the transfer: dict gopher gophers ldap ldaps rtmp rtmps or telnet. The earliest affected version is 7.77.0.

CVSS3: 8.1
3%
Низкий
6 месяцев назад
msrc логотип
CVSS3: 8.8
6%
Низкий
почти 2 года назад
msrc логотип
CVE-2022-4285

An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
msrc логотип
CVE-2022-42722

In the Linux kernel 5.8 through 5.19.x before 5.19.16 local attackers able to inject WLAN frames into the mac80211 stack could cause a NULL pointer dereference denial-of-service attack against the beacon protection of P2P devices.

CVSS3: 5.5
1%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-42721

A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked list and in turn potentially execute code.

CVSS3: 5.5
1%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-42720

Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger use-after-free conditions to potentially execute code.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-42719

A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before 5.19.16 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-42717

An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-42703

mm/rmap.c in the Linux kernel before 5.19.7 has a use-after-free related to leaf anon_vma double reuse.

CVSS3: 5.5
1%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-4262

Chromium: CVE-2022-4262 Type Confusion in V8

15%
Средний
больше 3 лет назад
msrc логотип
CVSS3: 5.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 5.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-42012

An issue was discovered in D-Bus before 1.12.24 1.13.x and 1.14.x before 1.14.4 and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-42011

An issue was discovered in D-Bus before 1.12.24 1.13.x and 1.14.x before 1.14.4 and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-42010

An issue was discovered in D-Bus before 1.12.24 1.13.x and 1.14.x before 1.14.4 and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-41974

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword which is mishandled because arithmetic ADD is used instead of bitwise OR.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-41973

multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling which could lead to controlled file writes outside of the /dev/shm directory. This could be used indirectly for local privilege escalation to root.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-4195

Chromium: CVE-2022-4195 Insufficient policy enforcement in Safe Browsing

0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-41953

Git clone remote code execution vulnerability in git-for-windows

CVSS3: 7.8
7%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-4194

Chromium: CVE-2022-4194 Use after free in Accessibility

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу