Количество 25 377
Количество 25 377
CVE-2022-0908
Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file.
CVE-2022-0907
Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources the fix is available with commit f2b656e2.
CVE-2022-0891
A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash potential information disclosure or any other context-dependent impact
CVE-2022-0865
Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources the fix is available with commit 5e180045.
CVE-2022-0854
A memory leak flaw was found in the Linux kernel’s DMA subsystem in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to read random memory from the kernel space.
CVE-2022-0850
A vulnerability was found in linux kernel where an information leak occurs via ext4_extent_header to userspace.
CVE-2022-0847
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.
CVE-2022-0811
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.
CVE-2022-0809
Chromium: CVE-2022-0809 Out of bounds memory access in WebXR
CVE-2022-0808
Chromium: CVE-2022-0808 Use after free in Chrome OS Shell
CVE-2022-0807
Chromium: CVE-2022-0807 Inappropriate implementation in Autofill
CVE-2022-0806
Chromium: CVE-2022-0806 Data leak in Canvas
CVE-2022-0805
Chromium: CVE-2022-0805 Use after free in Browser Switcher
CVE-2022-0804
Chromium: CVE-2022-0804 Inappropriate implementation in Full screen mode
CVE-2022-0803
Chromium: CVE-2022-0803 Inappropriate implementation in Permissions
CVE-2022-0802
Chromium: CVE-2022-0802 Inappropriate implementation in Full screen mode
CVE-2022-0801
Chromium: CVE-2022-0801 Inappropriate implementation in HTML parser
CVE-2022-0800
Chromium: CVE-2022-0800 Heap buffer overflow in Cast UI
CVE-2022-0799
Chromium: CVE-2022-0799 Insufficient policy enforcement in Installer
CVE-2022-0798
Chromium: CVE-2022-0798 Use after free in MediaStream
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-0908 Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file. | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
CVE-2022-0907 Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources the fix is available with commit f2b656e2. | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
CVE-2022-0891 A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash potential information disclosure or any other context-dependent impact | CVSS3: 7.1 | 2% Низкий | больше 4 лет назад | |
CVE-2022-0865 Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources the fix is available with commit 5e180045. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
CVE-2022-0854 A memory leak flaw was found in the Linux kernel’s DMA subsystem in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to read random memory from the kernel space. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2022-0850 A vulnerability was found in linux kernel where an information leak occurs via ext4_extent_header to userspace. | CVSS3: 7.1 | 0% Низкий | почти 4 года назад | |
CVE-2022-0847 A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system. | CVSS3: 7.8 | 89% Высокий | больше 4 лет назад | |
CVE-2022-0811 A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed. | CVSS3: 8.8 | 19% Средний | 11 месяцев назад | |
CVE-2022-0809 Chromium: CVE-2022-0809 Out of bounds memory access in WebXR | 1% Низкий | больше 4 лет назад | ||
CVE-2022-0808 Chromium: CVE-2022-0808 Use after free in Chrome OS Shell | 1% Низкий | больше 4 лет назад | ||
CVE-2022-0807 Chromium: CVE-2022-0807 Inappropriate implementation in Autofill | 1% Низкий | больше 4 лет назад | ||
CVE-2022-0806 Chromium: CVE-2022-0806 Data leak in Canvas | 1% Низкий | больше 4 лет назад | ||
CVE-2022-0805 Chromium: CVE-2022-0805 Use after free in Browser Switcher | 1% Низкий | больше 4 лет назад | ||
CVE-2022-0804 Chromium: CVE-2022-0804 Inappropriate implementation in Full screen mode | 1% Низкий | больше 4 лет назад | ||
CVE-2022-0803 Chromium: CVE-2022-0803 Inappropriate implementation in Permissions | 1% Низкий | больше 4 лет назад | ||
CVE-2022-0802 Chromium: CVE-2022-0802 Inappropriate implementation in Full screen mode | 1% Низкий | больше 4 лет назад | ||
CVE-2022-0801 Chromium: CVE-2022-0801 Inappropriate implementation in HTML parser | 1% Низкий | больше 4 лет назад | ||
CVE-2022-0800 Chromium: CVE-2022-0800 Heap buffer overflow in Cast UI | 1% Низкий | больше 4 лет назад | ||
CVE-2022-0799 Chromium: CVE-2022-0799 Insufficient policy enforcement in Installer | 1% Низкий | больше 4 лет назад | ||
CVE-2022-0798 Chromium: CVE-2022-0798 Use after free in MediaStream | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу