Количество 26 087
Количество 26 087
CVE-2022-3626
LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c:340 when called from processCropSelections tools/tiffcrop.c:7619 allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources the fix is available with commit 236b7191.
CVE-2022-36227
CVE-2022-36123
The Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV guest OS users to cause a denial of service or gain privileges.
CVE-2022-36114
Extracting malicious crates can fill the file system
CVE-2022-36113
Extracting malicious crates can corrupt arbitrary files
CVE-2022-3606
Linux Kernel BPF libbpf.c find_prog_by_sec_insn null pointer dereference
CVE-2022-36069
Poetry Argument Injection vulnerability can lead to local Code Execution
CVE-2022-36055
Denial of service in Helm
CVE-2022-36049
Flux2 Helm Controller denial of service
CVE-2022-36033
jsoup may not sanitize Cross-Site Scripting (XSS) attempts if SafeList.preserveRelativeLinks is enabled
CVE-2022-3602
OpenSSL: CVE-2022-3602 X.509 certificate verification buffer overrun
CVE-2022-36021
Redis string pattern matching can be abused to achieve Denial of Service
CVE-2022-3599
LibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345 allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources the fix is available with commit e8131125.
CVE-2022-3598
LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604 allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources the fix is available with commit cfbb883b.
CVE-2022-3597
LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection tools/tiffcrop.c:6826 allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources the fix is available with commit 236b7191.
CVE-2022-35977
Integer overflow in certain command arguments can drive Redis to OOM panic
CVE-2022-3595
Linux Kernel CIFS sess.c sess_free_buffer double free
CVE-2022-3594
Linux Kernel BPF r8152.c intr_callback logging of excessive data
CVE-2022-3586
A flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue function used the socket buffer (SKB) cb field after the same SKB had been enqueued (and freed) into a child qdisc. This flaw allows a local unprivileged user to crash the system causing a denial of service.
CVE-2022-35841
Windows Enterprise App Management Service Remote Code Execution Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-3626 LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c:340 when called from processCropSelections tools/tiffcrop.c:7619 allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources the fix is available with commit 236b7191. | CVSS3: 6.5 | 1% Низкий | почти 4 года назад | |
CVSS3: 9.8 | 2% Низкий | больше 3 лет назад | ||
CVE-2022-36123 The Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV guest OS users to cause a denial of service or gain privileges. | CVSS3: 7.8 | 1% Низкий | около 4 лет назад | |
CVE-2022-36114 Extracting malicious crates can fill the file system | CVSS3: 4.8 | 1% Низкий | 11 месяцев назад | |
CVE-2022-36113 Extracting malicious crates can corrupt arbitrary files | CVSS3: 4.6 | 1% Низкий | 11 месяцев назад | |
CVE-2022-3606 Linux Kernel BPF libbpf.c find_prog_by_sec_insn null pointer dereference | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
CVE-2022-36069 Poetry Argument Injection vulnerability can lead to local Code Execution | CVSS3: 7.3 | 1% Низкий | 10 месяцев назад | |
CVE-2022-36055 Denial of service in Helm | CVSS3: 6.5 | 1% Низкий | почти 4 года назад | |
CVE-2022-36049 Flux2 Helm Controller denial of service | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
CVE-2022-36033 jsoup may not sanitize Cross-Site Scripting (XSS) attempts if SafeList.preserveRelativeLinks is enabled | CVSS3: 6.1 | 1% Низкий | 10 месяцев назад | |
CVE-2022-3602 OpenSSL: CVE-2022-3602 X.509 certificate verification buffer overrun | 91% Критический | почти 4 года назад | ||
CVE-2022-36021 Redis string pattern matching can be abused to achieve Denial of Service | CVSS3: 5.5 | 60% Средний | больше 3 лет назад | |
CVE-2022-3599 LibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345 allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources the fix is available with commit e8131125. | CVSS3: 6.5 | 1% Низкий | почти 4 года назад | |
CVE-2022-3598 LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604 allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources the fix is available with commit cfbb883b. | CVSS3: 6.5 | 1% Низкий | почти 4 года назад | |
CVE-2022-3597 LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection tools/tiffcrop.c:6826 allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources the fix is available with commit 236b7191. | CVSS3: 6.5 | 1% Низкий | почти 4 года назад | |
CVE-2022-35977 Integer overflow in certain command arguments can drive Redis to OOM panic | CVSS3: 5.5 | 37% Средний | больше 3 лет назад | |
CVE-2022-3595 Linux Kernel CIFS sess.c sess_free_buffer double free | CVSS3: 5.5 | 0% Низкий | почти 4 года назад | |
CVE-2022-3594 Linux Kernel BPF r8152.c intr_callback logging of excessive data | CVSS3: 5.3 | 2% Низкий | почти 4 года назад | |
CVE-2022-3586 A flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue function used the socket buffer (SKB) cb field after the same SKB had been enqueued (and freed) into a child qdisc. This flaw allows a local unprivileged user to crash the system causing a denial of service. | CVSS3: 5.5 | 0% Низкий | почти 4 года назад | |
CVE-2022-35841 Windows Enterprise App Management Service Remote Code Execution Vulnerability | CVSS3: 8.8 | 3% Низкий | почти 4 года назад |
Уязвимостей на страницу