Количество 26 087
Количество 26 087
CVE-2022-41040
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2022-41039
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
CVE-2022-41038
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2022-41037
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2022-41036
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2022-41035
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2022-41034
Visual Studio Code Remote Code Execution Vulnerability
CVE-2022-41033
Windows COM+ Event System Service Elevation of Privilege Vulnerability
CVE-2022-41032
NuGet Client Elevation of Privilege Vulnerability
CVE-2022-41031
Microsoft Word Remote Code Execution Vulnerability
CVE-2022-4095
CVE-2022-40898
CVE-2022-40897
Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.
CVE-2022-40896
A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
CVE-2022-4087
iPXE TLS tls.c tls_new_ciphertext information exposure
CVE-2022-40768
drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case.
CVE-2022-40674
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
CVE-2022-40617
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake or sends an excessive amount of application data.
CVE-2022-4055
When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.
CVE-2022-40476
A null pointer dereference issue was discovered in fs/io_uring.c in the Linux kernel before 5.15.62. A local user could use this flaw to crash the system or potentially cause a denial of service.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-41040 Microsoft Exchange Server Elevation of Privilege Vulnerability | CVSS3: 8.8 | 100% Критический | почти 4 года назад | |
CVE-2022-41039 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | CVSS3: 8.1 | 1% Низкий | почти 4 года назад | |
CVE-2022-41038 Microsoft SharePoint Server Remote Code Execution Vulnerability | CVSS3: 8.8 | 3% Низкий | почти 4 года назад | |
CVE-2022-41037 Microsoft SharePoint Server Remote Code Execution Vulnerability | CVSS3: 8.8 | 2% Низкий | почти 4 года назад | |
CVE-2022-41036 Microsoft SharePoint Server Remote Code Execution Vulnerability | CVSS3: 8.8 | 2% Низкий | почти 4 года назад | |
CVE-2022-41035 Microsoft Edge (Chromium-based) Spoofing Vulnerability | CVSS3: 5.3 | 1% Низкий | почти 4 года назад | |
CVE-2022-41034 Visual Studio Code Remote Code Execution Vulnerability | CVSS3: 7.8 | 67% Средний | почти 4 года назад | |
CVE-2022-41033 Windows COM+ Event System Service Elevation of Privilege Vulnerability | CVSS3: 7.8 | 2% Низкий | почти 4 года назад | |
CVE-2022-41032 NuGet Client Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | почти 4 года назад | |
CVE-2022-41031 Microsoft Word Remote Code Execution Vulnerability | CVSS3: 7.8 | 1% Низкий | почти 4 года назад | |
CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | ||
CVSS3: 7.5 | 3% Низкий | почти 2 года назад | ||
CVE-2022-40897 Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py. | CVSS3: 5.9 | 3% Низкий | 6 месяцев назад | |
CVE-2022-40896 A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer. | CVSS3: 5.5 | 1% Низкий | 6 дней назад | |
CVE-2022-4087 iPXE TLS tls.c tls_new_ciphertext information exposure | 0% Низкий | 11 месяцев назад | ||
CVE-2022-40768 drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case. | CVSS3: 5.5 | 0% Низкий | почти 4 года назад | |
CVE-2022-40674 libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c. | CVSS3: 8.1 | 2% Низкий | 6 месяцев назад | |
CVE-2022-40617 strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake or sends an excessive amount of application data. | CVSS3: 7.5 | 2% Низкий | почти 4 года назад | |
CVE-2022-4055 When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked. | CVSS3: 7.4 | 1% Низкий | больше 1 года назад | |
CVE-2022-40476 A null pointer dereference issue was discovered in fs/io_uring.c in the Linux kernel before 5.15.62. A local user could use this flaw to crash the system or potentially cause a denial of service. | CVSS3: 5.5 | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу