Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 511

Количество 56 511

redhat логотип

CVE-2022-48571

около 3 лет назад

memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-48566

около 3 лет назад

An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2022-48565

около 3 лет назад

An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-48564

около 3 лет назад

read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-48560

около 3 лет назад

A use-after-free exists in Python through 3.9 via heappushpop in heapq.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-48554

больше 4 лет назад

File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-48541

около 3 лет назад

A memory leak in ImageMagick 7.0.10-45 and 6.9.11-22 allows remote attackers to perform a denial of service via the "identify -help" command.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2022-48522

около 3 лет назад

In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-48503

около 3 лет назад

The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2022-48502

почти 4 года назад

An issue was discovered in the Linux kernel before 6.2. The ntfs3 subsystem does not properly check for correctness during disk reads, leading to an out-of-bounds read in ntfs_set_ea in fs/ntfs3/xattr.c.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2022-48468

больше 3 лет назад

protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2022-4842

около 4 лет назад

A flaw NULL Pointer Dereference in the Linux kernel NTFS3 driver function attr_punch_hole() was found. A local user could use this flaw to crash the system.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-48425

больше 3 лет назад

In the Linux kernel through 6.2.7, fs/ntfs3/inode.c has an invalid kfree because it does not validate MFT flags before replaying logs.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2022-48424

больше 3 лет назад

In the Linux kernel before 6.1.3, fs/ntfs3/inode.c does not validate the attribute name offset. An unhandled page fault may occur.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2022-48423

больше 3 лет назад

In the Linux kernel before 6.1.3, fs/ntfs3/record.c does not validate resident attribute names. An out-of-bounds write may occur.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2022-48345

больше 3 лет назад

sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2022-48340

больше 3 лет назад

In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-48339

больше 3 лет назад

An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file name or directory name contains shell metacharacters, code may be executed.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-48338

больше 3 лет назад

An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2022-48337

больше 3 лет назад

GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For example, a victim may use the "etags -u *" command (suggested in the etags documentation) in a situation where the current working directory has contents that depend on untrusted input.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-48571

memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.

CVSS3: 5.3
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-48566

An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.

CVSS3: 5.9
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-48565

An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.

CVSS3: 7.8
5%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-48564

read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.

CVSS3: 6.5
2%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-48560

A use-after-free exists in Python through 3.9 via heappushpop in heapq.

CVSS3: 7.5
2%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-48554

File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-48541

A memory leak in ImageMagick 7.0.10-45 and 6.9.11-22 allows remote attackers to perform a denial of service via the "identify -help" command.

CVSS3: 7.1
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-48522

In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.

CVSS3: 5.5
3%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-48503

The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution.

CVSS3: 8.8
3%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-48502

An issue was discovered in the Linux kernel before 6.2. The ntfs3 subsystem does not properly check for correctness during disk reads, leading to an out-of-bounds read in ntfs_set_ea in fs/ntfs3/xattr.c.

CVSS3: 7.1
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-48468

protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member.

CVSS3: 6.2
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-4842

A flaw NULL Pointer Dereference in the Linux kernel NTFS3 driver function attr_punch_hole() was found. A local user could use this flaw to crash the system.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-48425

In the Linux kernel through 6.2.7, fs/ntfs3/inode.c has an invalid kfree because it does not validate MFT flags before replaying logs.

CVSS3: 7
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-48424

In the Linux kernel before 6.1.3, fs/ntfs3/inode.c does not validate the attribute name offset. An unhandled page fault may occur.

CVSS3: 7
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-48423

In the Linux kernel before 6.1.3, fs/ntfs3/record.c does not validate resident attribute names. An out-of-bounds write may occur.

CVSS3: 7
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-48345

sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-48340

In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-48339

An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file name or directory name contains shell metacharacters, code may be executed.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-48338

An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.

CVSS3: 7.3
2%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-48337

GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For example, a victim may use the "etags -u *" command (suggested in the etags documentation) in a situation where the current working directory has contents that depend on untrusted input.

CVSS3: 7.3
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу