Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 378

Количество 56 378

redhat логотип

CVE-2022-38266

почти 4 года назад

An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-38251

около 4 лет назад

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Settings page under the Admin panel.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2022-38250

около 4 лет назад

Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-38249

около 4 лет назад

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2022-38248

около 4 лет назад

Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2022-38247

около 4 лет назад

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under the Admin panel.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2022-38223

около 4 лет назад

There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-3821

около 4 лет назад

An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-38178

почти 4 года назад

By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-38177

почти 4 года назад

By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-38150

около 4 лет назад

In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This is fixed in 7.0.3 and 7.1.1.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-38149

около 4 лет назад

HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.Execute method, when given a template using Vault secret contents incorrectly. Fixed in 0.27.3, 0.28.3, and 0.29.2.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-38096

около 4 лет назад

A NULL pointer dereference vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-38090

больше 3 лет назад

Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potentially enable information disclosure via local access.

CVSS3: 6
EPSS: Низкий
redhat логотип

CVE-2022-38076

около 3 лет назад

Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 3.8
EPSS: Низкий
redhat логотип

CVE-2022-38065

почти 4 года назад

A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2022-38060

около 4 лет назад

A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-38023

больше 3 лет назад

Netlogon RPC Elevation of Privilege Vulnerability

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2022-38013

почти 4 года назад

.NET Core and Visual Studio Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-37967

больше 3 лет назад

Windows Kerberos Elevation of Privilege Vulnerability

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-38266

An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.

CVSS3: 5.5
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-38251

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Settings page under the Admin panel.

CVSS3: 4.8
2%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-38250

Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-38249

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4.

CVSS3: 6.1
2%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-38248

Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.

CVSS3: 6.1
2%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-38247

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under the Admin panel.

CVSS3: 4.8
2%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-38223

There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-3821

An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-38178

By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.

CVSS3: 7.5
3%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-38177

By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.

CVSS3: 7.5
3%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-38150

In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This is fixed in 7.0.3 and 7.1.1.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-38149

HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.Execute method, when given a template using Vault secret contents incorrectly. Fixed in 0.27.3, 0.28.3, and 0.29.2.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-38096

A NULL pointer dereference vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).

CVSS3: 5.5
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-38090

Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potentially enable information disclosure via local access.

CVSS3: 6
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-38076

Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 3.8
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-38065

A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-38060

A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-38023

Netlogon RPC Elevation of Privilege Vulnerability

CVSS3: 8.1
3%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-38013

.NET Core and Visual Studio Denial of Service Vulnerability

CVSS3: 7.5
3%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-37967

Windows Kerberos Elevation of Privilege Vulnerability

CVSS3: 7.2
4%
Низкий
больше 3 лет назад

Уязвимостей на страницу