Количество 25 379
Количество 25 379
CVE-2022-22824
defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
CVE-2022-22823
build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
CVE-2022-22822
addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
CVE-2022-22736
If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directory for system libraries. However the install directory is not world-writable by default.<br>*This bug only affects Firefox for Windows in a non-default installation. Other operating systems are unaffected.*. This vulnerability affects Firefox < 96.
CVE-2022-22721
core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody
CVE-2022-22720
HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier
CVE-2022-22719
mod_lua Use of uninitialized value of in r:parsebody
CVE-2022-22718
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2022-22717
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2022-22716
Microsoft Excel Information Disclosure Vulnerability
CVE-2022-22715
Named Pipe File System Elevation of Privilege Vulnerability
CVE-2022-22713
Windows Hyper-V Denial of Service Vulnerability
CVE-2022-22712
Windows Hyper-V Denial of Service Vulnerability
CVE-2022-22711
Windows BitLocker Information Disclosure Vulnerability
CVE-2022-22710
Windows Common Log File System Driver Denial of Service Vulnerability
CVE-2022-22709
VP9 Video Extensions Remote Code Execution Vulnerability
CVE-2022-2264
Heap-based Buffer Overflow in vim/vim
CVE-2022-2257
Out-of-bounds Read in vim/vim
CVE-2022-22576
An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S) IMAP(S) POP3(S) and LDAP(S) (openldap only).
CVE-2022-2255
A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-22824 defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
CVE-2022-22823 build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
CVE-2022-22822 addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. | CVSS3: 9.8 | 5% Низкий | больше 4 лет назад | |
CVE-2022-22736 If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directory for system libraries. However the install directory is not world-writable by default.<br>*This bug only affects Firefox for Windows in a non-default installation. Other operating systems are unaffected.*. This vulnerability affects Firefox < 96. | 0% Низкий | 11 месяцев назад | ||
CVE-2022-22721 core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody | CVSS3: 9.1 | 42% Средний | больше 4 лет назад | |
CVE-2022-22720 HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier | CVSS3: 9.8 | 28% Средний | больше 4 лет назад | |
CVE-2022-22719 mod_lua Use of uninitialized value of in r:parsebody | CVSS3: 7.5 | 70% Средний | больше 4 лет назад | |
CVE-2022-22718 Windows Print Spooler Elevation of Privilege Vulnerability | CVSS3: 7.8 | 18% Средний | больше 4 лет назад | |
CVE-2022-22717 Windows Print Spooler Elevation of Privilege Vulnerability | CVSS3: 7 | 1% Низкий | больше 4 лет назад | |
CVE-2022-22716 Microsoft Excel Information Disclosure Vulnerability | CVSS3: 5.5 | 5% Низкий | больше 4 лет назад | |
CVE-2022-22715 Named Pipe File System Elevation of Privilege Vulnerability | CVSS3: 7.8 | 13% Средний | больше 4 лет назад | |
CVE-2022-22713 Windows Hyper-V Denial of Service Vulnerability | CVSS3: 5.6 | 1% Низкий | больше 4 лет назад | |
CVE-2022-22712 Windows Hyper-V Denial of Service Vulnerability | CVSS3: 5.6 | 1% Низкий | больше 4 лет назад | |
CVE-2022-22711 Windows BitLocker Information Disclosure Vulnerability | CVSS3: 5.7 | 1% Низкий | около 4 лет назад | |
CVE-2022-22710 Windows Common Log File System Driver Denial of Service Vulnerability | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
CVE-2022-22709 VP9 Video Extensions Remote Code Execution Vulnerability | CVSS3: 7.8 | 2% Низкий | больше 4 лет назад | |
CVE-2022-2264 Heap-based Buffer Overflow in vim/vim | CVSS3: 7.8 | 1% Низкий | около 4 лет назад | |
CVE-2022-2257 Out-of-bounds Read in vim/vim | CVSS3: 7.8 | 1% Низкий | около 4 лет назад | |
CVE-2022-22576 An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S) IMAP(S) POP3(S) and LDAP(S) (openldap only). | CVSS3: 8.1 | 2% Низкий | около 4 лет назад | |
CVE-2022-2255 A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing. | CVSS3: 7.5 | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу