Количество 26 087
Количество 26 087
CVE-2022-37958
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
CVE-2022-37957
Windows Kernel Elevation of Privilege Vulnerability
CVE-2022-37956
Windows Kernel Elevation of Privilege Vulnerability
CVE-2022-37955
Windows Group Policy Elevation of Privilege Vulnerability
CVE-2022-37954
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2022-3786
OpenSSL: CVE-2022-3786 X.509 certificate verification buffer overrun
CVE-2022-3775
Redhat: CVE-2022-3775 grub2 - Heap based out-of-bounds write when rendering certain Unicode sequences
CVE-2022-3775-M
CVE-2022-37616
A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."
CVE-2022-37603
A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.
CVE-2022-37601
CVE-2022-37454
The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.
CVE-2022-37436
Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting
CVE-2022-37434
CVE-2022-3736
named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries
CVE-2022-3723
Chromium: CVE-2022-3723 Type Confusion in V8
CVE-2022-3715
A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems.
CVE-2022-3707
A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VGA card system resource overload causing a fail in the intel_gvt_dma_map_guest_page function. This issue could allow a local user to crash the system.
CVE-2022-3705
vim autocmd quickfix.c qf_update_buffer use after free
CVE-2022-3697
A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-37958 SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | CVSS3: 8.1 | 86% Высокий | почти 4 года назад | |
CVE-2022-37957 Windows Kernel Elevation of Privilege Vulnerability | CVSS3: 7.8 | 14% Средний | почти 4 года назад | |
CVE-2022-37956 Windows Kernel Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | почти 4 года назад | |
CVE-2022-37955 Windows Group Policy Elevation of Privilege Vulnerability | CVSS3: 7.8 | 2% Низкий | почти 4 года назад | |
CVE-2022-37954 DirectX Graphics Kernel Elevation of Privilege Vulnerability | CVSS3: 7.8 | 45% Средний | почти 4 года назад | |
CVE-2022-3786 OpenSSL: CVE-2022-3786 X.509 certificate verification buffer overrun | 92% Критический | почти 4 года назад | ||
CVE-2022-3775 Redhat: CVE-2022-3775 grub2 - Heap based out-of-bounds write when rendering certain Unicode sequences | CVSS3: 7.1 | 1% Низкий | почти 2 года назад | |
| больше 3 лет назад | ||||
CVE-2022-37616 A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted." | CVSS3: 9.8 | 2% Низкий | 6 месяцев назад | |
CVE-2022-37603 A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js. | 2% Низкий | 11 месяцев назад | ||
CVSS3: 9.8 | 3% Низкий | больше 3 лет назад | ||
CVE-2022-37454 The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface. | CVSS3: 9.8 | 5% Низкий | больше 3 лет назад | |
CVE-2022-37436 Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting | CVSS3: 5.3 | 58% Средний | около 1 года назад | |
CVSS3: 9.8 | 18% Средний | около 4 лет назад | ||
CVE-2022-3736 named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries | CVSS3: 7.5 | 49% Средний | больше 3 лет назад | |
CVE-2022-3723 Chromium: CVE-2022-3723 Type Confusion in V8 | 8% Низкий | почти 4 года назад | ||
CVE-2022-3715 A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems. | CVSS3: 7.8 | 0% Низкий | 10 месяцев назад | |
CVE-2022-3707 A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VGA card system resource overload causing a fail in the intel_gvt_dma_map_guest_page function. This issue could allow a local user to crash the system. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
CVE-2022-3705 vim autocmd quickfix.c qf_update_buffer use after free | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
CVE-2022-3697 A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw allows an attacker to take advantage of this issue as the module is handling the parameter insecurely, leading to the password leaking in the logs. | CVSS3: 7.5 | 1% Низкий | 10 месяцев назад |
Уязвимостей на страницу