Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 378

Количество 56 378

redhat логотип

CVE-2022-35020

около 4 лет назад

Advancecomp v2.3 was discovered to contain a heap buffer overflow via the component __interceptor_memcpy at /sanitizer_common/sanitizer_common_interceptors.inc.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-35019

около 4 лет назад

Advancecomp v2.3 was discovered to contain a segmentation fault.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-35018

около 4 лет назад

Advancecomp v2.3 was discovered to contain a segmentation fault.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-35017

около 4 лет назад

Advancecomp v2.3 was discovered to contain a heap buffer overflow.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-35016

около 4 лет назад

Advancecomp v2.3 was discovered to contain a heap buffer overflow.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-35015

около 4 лет назад

Advancecomp v2.3 was discovered to contain a heap buffer overflow via le_uint32_read at /lib/endianrw.h.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-35014

около 4 лет назад

Advancecomp v2.3 contains a segmentation fault.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-3500

почти 4 года назад

A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts for that host leaving it in an attested state but not verifying that anymore.

CVSS3: 5.1
EPSS: Низкий
redhat логотип

CVE-2022-3491

почти 4 года назад

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-34918

около 4 лет назад

An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but must start with an unprivileged user namespace to obtain CAP_NET_ADMIN access.) This can be fixed in nft_setelem_parse_data in net/netfilter/nf_tables_api.c.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-34917

почти 4 года назад

A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated clients to allocate large amounts of memory on brokers. This can lead to brokers hitting OutOfMemoryException and causing denial of service. Example scenarios: - Kafka cluster without authentication: Any clients able to establish a network connection to a broker can trigger the issue. - Kafka cluster with SASL authentication: Any clients able to establish a network connection to a broker, without the need for valid SASL credentials, can trigger the issue. - Kafka cluster with TLS authentication: Only clients able to successfully authenticate via TLS can trigger the issue. We advise the users to upgrade the Kafka installations to one of the 3.2.3, 3.1.2, 3.0.2, 2.8.2 versions.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-34916

около 4 лет назад

Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2022-34912

около 4 лет назад

An issue was discovered in MediaWiki before 1.37.3 and 1.38.x before 1.38.1. The contributions-title, used on Special:Contributions, is used as page title without escaping. Hence, in a non-default configuration where a username contains HTML entities, it won't be escaped.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2022-34911

около 4 лет назад

An issue was discovered in MediaWiki before 1.35.7, 1.36.x and 1.37.x before 1.37.3, and 1.38.x before 1.38.1. XSS can occur in configurations that allow a JavaScript payload in a username. After account creation, when it sets the page title to "Welcome" followed by the username, the username is not escaped: SpecialCreateAccount::successfulAction() calls ::showSuccessPage() with a message as second parameter, and OutputPage::setPageTitle() uses text().

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2022-34903

около 4 лет назад

GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2022-3488

больше 3 лет назад

Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can cause BIND to exit with an assertion failure. 'Broken' in this context is anything that would cause the resolver to reject the query response, such as a mismatch between query and answer name. This issue affects BIND 9 versions 9.11.4-S1 through 9.11.37-S1 and 9.16.8-S1 through 9.16.36-S1.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2022-3479

около 4 лет назад

A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or crash.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-34749

около 4 лет назад

In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-34716

около 4 лет назад

.NET Spoofing Vulnerability

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2022-3466

почти 4 года назад

The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022-27652, which was previously fixed in OCP 4.9.41 and 4.10.12 via RHBA-2022:5433 and RHSA-2022:1600. This issue could allow an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. For more details, see https://access.redhat.com/security/cve/CVE-2022-27652.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-35020

Advancecomp v2.3 was discovered to contain a heap buffer overflow via the component __interceptor_memcpy at /sanitizer_common/sanitizer_common_interceptors.inc.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-35019

Advancecomp v2.3 was discovered to contain a segmentation fault.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-35018

Advancecomp v2.3 was discovered to contain a segmentation fault.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-35017

Advancecomp v2.3 was discovered to contain a heap buffer overflow.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-35016

Advancecomp v2.3 was discovered to contain a heap buffer overflow.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-35015

Advancecomp v2.3 was discovered to contain a heap buffer overflow via le_uint32_read at /lib/endianrw.h.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-35014

Advancecomp v2.3 contains a segmentation fault.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-3500

A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts for that host leaving it in an attested state but not verifying that anymore.

CVSS3: 5.1
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-3491

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-34918

An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but must start with an unprivileged user namespace to obtain CAP_NET_ADMIN access.) This can be fixed in nft_setelem_parse_data in net/netfilter/nf_tables_api.c.

CVSS3: 7.8
5%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-34917

A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated clients to allocate large amounts of memory on brokers. This can lead to brokers hitting OutOfMemoryException and causing denial of service. Example scenarios: - Kafka cluster without authentication: Any clients able to establish a network connection to a broker can trigger the issue. - Kafka cluster with SASL authentication: Any clients able to establish a network connection to a broker, without the need for valid SASL credentials, can trigger the issue. - Kafka cluster with TLS authentication: Only clients able to successfully authenticate via TLS can trigger the issue. We advise the users to upgrade the Kafka installations to one of the 3.2.3, 3.1.2, 3.0.2, 2.8.2 versions.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-34916

Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol.

CVSS3: 8.1
3%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-34912

An issue was discovered in MediaWiki before 1.37.3 and 1.38.x before 1.38.1. The contributions-title, used on Special:Contributions, is used as page title without escaping. Hence, in a non-default configuration where a username contains HTML entities, it won't be escaped.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-34911

An issue was discovered in MediaWiki before 1.35.7, 1.36.x and 1.37.x before 1.37.3, and 1.38.x before 1.38.1. XSS can occur in configurations that allow a JavaScript payload in a username. After account creation, when it sets the page title to "Welcome" followed by the username, the username is not escaped: SpecialCreateAccount::successfulAction() calls ::showSuccessPage() with a message as second parameter, and OutputPage::setPageTitle() uses text().

CVSS3: 6.1
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-34903

GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.

CVSS3: 5.9
3%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-3488

Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can cause BIND to exit with an assertion failure. 'Broken' in this context is anything that would cause the resolver to reject the query response, such as a mismatch between query and answer name. This issue affects BIND 9 versions 9.11.4-S1 through 9.11.37-S1 and 9.16.8-S1 through 9.16.36-S1.

CVSS3: 7.5
19%
Средний
больше 3 лет назад
redhat логотип
CVE-2022-3479

A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or crash.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-34749

In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-34716

.NET Spoofing Vulnerability

CVSS3: 5.9
2%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-3466

The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022-27652, which was previously fixed in OCP 4.9.41 and 4.10.12 via RHBA-2022:5433 and RHSA-2022:1600. This issue could allow an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. For more details, see https://access.redhat.com/security/cve/CVE-2022-27652.

CVSS3: 4.8
0%
Низкий
почти 4 года назад

Уязвимостей на страницу