Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 378

Количество 56 378

redhat логотип

CVE-2022-4145

почти 4 года назад

A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2022-4144

почти 4 года назад

An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into adjacent pages. A malicious guest user could use this flaw to crash the QEMU process on the host causing a denial of service condition.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-41420

почти 4 года назад

nasm v2.16 was discovered to contain a stack overflow in the Ndisasm component

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-4141

почти 4 года назад

Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-41409

около 3 лет назад

Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-41404

почти 4 года назад

An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-4139

почти 4 года назад

An incorrect TLB flush issue was found in the Linux kernel’s GPU i915 kernel driver, potentially leading to random memory corruption or data leaks. This flaw could allow a local user to crash the system or escalate their privileges on the system.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2022-4137

больше 3 лет назад

A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a malicious link to insert an arbitrary URI into a Keycloak error page. This flaw requires a user or administrator to interact with a link in order to be vulnerable. This may compromise user details, allowing it to be changed or collected by an attacker.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2022-41354

больше 3 лет назад

An access control issue in Argo CD v2.4.12 and below allows unauthenticated attackers to enumerate existing applications.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-4134

почти 4 года назад

A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2022-4133

почти 4 года назад

A reflected Cross-site scripting (XSS) vulnerability was found in the Red Hat OpenStack Platform dashboard. This issue could allow an attacker to trick a user into pasting malicious code in the “Allocation Pools” instance.

EPSS: Низкий
redhat логотип

CVE-2022-4132

почти 4 года назад

A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if configured that way (repeatedly hitting the login page).

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2022-41323

почти 4 года назад

In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-41318

почти 4 года назад

A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2022-41317

почти 4 года назад

An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, there can be Exposure of Sensitive Information about clients using the proxy via an HTTPS request to an internal cache manager URL. This is fixed in 5.7.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-41316

почти 4 года назад

HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-4130

больше 3 лет назад

A blind site-to-site request forgery vulnerability was found in Satellite server. It is possible to trigger an external interaction to an attacker's server by modifying the Referer header in an HTTP request of specific resources in the server.

CVSS3: 3.5
EPSS: Низкий
redhat логотип

CVE-2022-4129

около 4 лет назад

A flaw was found in the Linux kernel's Layer 2 Tunneling Protocol (L2TP). A missing lock when clearing sk_user_data can lead to a race condition and NULL pointer dereference. A local user could use this flaw to potentially crash the system causing a denial of service.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-4128

около 4 лет назад

A NULL pointer dereference issue was discovered in the Linux kernel in the MPTCP protocol when traversing the subflow list at disconnect time. A local user could use this flaw to potentially crash the system causing a denial of service.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-4127

около 4 лет назад

A NULL pointer dereference issue was discovered in the Linux kernel in io_files_update_with_index_alloc. A local user could use this flaw to potentially crash the system causing a denial of service.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-4145

A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation.

CVSS3: 4.3
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-4144

An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into adjacent pages. A malicious guest user could use this flaw to crash the QEMU process on the host causing a denial of service condition.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-41420

nasm v2.16 was discovered to contain a stack overflow in the Ndisasm component

CVSS3: 5.5
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-4141

Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-41409

Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.

CVSS3: 5.3
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-41404

An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-4139

An incorrect TLB flush issue was found in the Linux kernel’s GPU i915 kernel driver, potentially leading to random memory corruption or data leaks. This flaw could allow a local user to crash the system or escalate their privileges on the system.

CVSS3: 7
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-4137

A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a malicious link to insert an arbitrary URI into a Keycloak error page. This flaw requires a user or administrator to interact with a link in order to be vulnerable. This may compromise user details, allowing it to be changed or collected by an attacker.

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-41354

An access control issue in Argo CD v2.4.12 and below allows unauthenticated attackers to enumerate existing applications.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-4134

A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.

CVSS3: 4.8
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-4133

A reflected Cross-site scripting (XSS) vulnerability was found in the Red Hat OpenStack Platform dashboard. This issue could allow an attacker to trick a user into pasting malicious code in the “Allocation Pools” instance.

почти 4 года назад
redhat логотип
CVE-2022-4132

A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if configured that way (repeatedly hitting the login page).

CVSS3: 5.9
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-41323

In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.

CVSS3: 7.5
3%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-41318

A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.

CVSS3: 8.6
3%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-41317

An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, there can be Exposure of Sensitive Information about clients using the proxy via an HTTPS request to an internal cache manager URL. This is fixed in 5.7.

CVSS3: 6.5
2%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-41316

HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-4130

A blind site-to-site request forgery vulnerability was found in Satellite server. It is possible to trigger an external interaction to an attacker's server by modifying the Referer header in an HTTP request of specific resources in the server.

CVSS3: 3.5
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-4129

A flaw was found in the Linux kernel's Layer 2 Tunneling Protocol (L2TP). A missing lock when clearing sk_user_data can lead to a race condition and NULL pointer dereference. A local user could use this flaw to potentially crash the system causing a denial of service.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-4128

A NULL pointer dereference issue was discovered in the Linux kernel in the MPTCP protocol when traversing the subflow list at disconnect time. A local user could use this flaw to potentially crash the system causing a denial of service.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-4127

A NULL pointer dereference issue was discovered in the Linux kernel in io_files_update_with_index_alloc. A local user could use this flaw to potentially crash the system causing a denial of service.

CVSS3: 5.5
0%
Низкий
около 4 лет назад

Уязвимостей на страницу