Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 378

Количество 56 378

redhat логотип

CVE-2022-4123

почти 4 года назад

A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.

CVSS3: 3.1
EPSS: Низкий
redhat логотип

CVE-2022-4122

почти 4 года назад

A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2022-41224

почти 4 года назад

Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control tooltips for this component.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2022-41222

около 5 лет назад

mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2022-41218

почти 4 года назад

In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-4116

почти 4 года назад

A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2022-41137

почти 2 года назад

Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it allows the deserialization of arbitrary data. In real deployments, the vulnerability can be exploited only by authenticated users/clients that were able to successfully establish a connection to the Metastore. From an API perspective any code that calls the unsafe method may be vulnerable unless it performs additional prerechecks on the input arguments.

CVSS3: 8.3
EPSS: Низкий
redhat логотип

CVE-2022-41089

больше 3 лет назад

.NET Framework Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2022-41032

почти 4 года назад

NuGet Client Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-40982

около 3 лет назад

Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-40964

около 3 лет назад

Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.9
EPSS: Низкий
redhat логотип

CVE-2022-40962

почти 4 года назад

Mozilla developers Nika Layzell, Timothy Nikkel, Sebastian Hengst, Andreas Pehrson, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 104 and Firefox ESR 102.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2022-40960

почти 4 года назад

Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-4095

почти 4 года назад

A use-after-free flaw was found in Linux kernel before 5.19.2. This issue occurs in cmd_hdl_filter in drivers/staging/rtl8712/rtl8712_cmd.c, allowing an attacker to launch a local denial of service attack and gain escalation of privileges.

CVSS3: 6.3
EPSS: Низкий
redhat логотип

CVE-2022-40959

почти 4 года назад

During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into untrusted subdocuments. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-40958

почти 4 года назад

By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite cookies from a secure context, leading to session fixation and other attacks. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2022-40957

почти 4 года назад

Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.<br>*This bug only affects Firefox on ARM64 platforms.*. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVSS3: 5.8
EPSS: Низкий
redhat логотип

CVE-2022-40956

почти 4 года назад

When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2022-40899

больше 3 лет назад

An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-40898

больше 3 лет назад

An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-4123

A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.

CVSS3: 3.1
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-4122

A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.

CVSS3: 5.9
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-41224

Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control tooltips for this component.

CVSS3: 7.4
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-41222

mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move.

CVSS3: 7
0%
Низкий
около 5 лет назад
redhat логотип
CVE-2022-41218

In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release.

CVSS3: 5.5
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-4116

A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution.

CVSS3: 7.5
33%
Средний
почти 4 года назад
redhat логотип
CVE-2022-41137

Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it allows the deserialization of arbitrary data. In real deployments, the vulnerability can be exploited only by authenticated users/clients that were able to successfully establish a connection to the Metastore. From an API perspective any code that calls the unsafe method may be vulnerable unless it performs additional prerechecks on the input arguments.

CVSS3: 8.3
2%
Низкий
почти 2 года назад
redhat логотип
CVE-2022-41089

.NET Framework Remote Code Execution Vulnerability

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-41032

NuGet Client Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-40982

Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 6.5
3%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-40964

Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.9
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-40962

Mozilla developers Nika Layzell, Timothy Nikkel, Sebastian Hengst, Andreas Pehrson, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 104 and Firefox ESR 102.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-40960

Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-4095

A use-after-free flaw was found in Linux kernel before 5.19.2. This issue occurs in cmd_hdl_filter in drivers/staging/rtl8712/rtl8712_cmd.c, allowing an attacker to launch a local denial of service attack and gain escalation of privileges.

CVSS3: 6.3
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-40959

During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into untrusted subdocuments. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-40958

By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite cookies from a secure context, leading to session fixation and other attacks. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVSS3: 6.1
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-40957

Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.<br>*This bug only affects Firefox on ARM64 platforms.*. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVSS3: 5.8
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-40956

When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVSS3: 6.1
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-40899

An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-40898

An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.

CVSS3: 7.5
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу