Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 378

Количество 56 378

redhat логотип

CVE-2022-3358

почти 4 года назад

OpenSSL supports creating a custom cipher via the legacy EVP_CIPHER_meth_new() function and associated function calls. This function was deprecated in OpenSSL 3.0 and application authors are instead encouraged to use the new provider mechanism in order to implement custom ciphers. OpenSSL versions 3.0.0 to 3.0.5 incorrectly handle legacy custom ciphers passed to the EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2() and EVP_CipherInit_ex2() functions (as well as other similarly named encryption and decryption initialisation functions). Instead of using the custom cipher directly it incorrectly tries to fetch an equivalent cipher from the available providers. An equivalent cipher is found based on the NID passed to EVP_CIPHER_meth_new(). This NID is supposed to represent the unique NID for a given cipher. However it is possible for an application to incorrectly pass NID_undef as this value in the call to EVP_CIPHER_meth_new(). When NID_undef is used in this way the OpenSSL encryption/decry...

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-3352

почти 4 года назад

Use After Free in GitHub repository vim/vim prior to 9.0.0614.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-3344

почти 4 года назад

A flaw was found in the KVM's AMD nested virtualization (SVM). A malicious L1 guest could purposely fail to intercept the shutdown of a cooperative nested guest (L2), possibly leading to a page fault and kernel panic in the host (L0).

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-3324

почти 4 года назад

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-33196

больше 3 лет назад

Incorrect default permissions in some memory controller configurations for some Intel(R) Xeon(R) Processors when using Intel(R) Software Guard Extensions which may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.2
EPSS: Низкий
redhat логотип

CVE-2022-33127

около 4 лет назад

The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a windows environment. This allows attackers to execute arbitrary commands via a crafted string.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-33124

около 4 лет назад

AIOHTTP 3.8.1 can report a "ValueError: Invalid IPv6 URL" outcome, which can lead to a Denial of Service (DoS). NOTE: multiple third parties dispute this issue because there is no example of a context in which denial of service would occur, and many common contexts have exception handing in the calling application

EPSS: Низкий
redhat логотип

CVE-2022-33105

около 4 лет назад

Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-33099

около 4 лет назад

An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-33082

около 4 лет назад

An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-33070

около 4 лет назад

Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVSS3: 3.1
EPSS: Низкий
redhat логотип

CVE-2022-33068

около 4 лет назад

An integer overflow in the component hb-ot-shape-fallback.cc of Harfbuzz v4.3.0 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-33065

почти 3 года назад

Multiple signed integers overflow in function au_read_header in src/au.c and in functions mat4_open and mat4_read_header in src/mat4.c in Libsndfile, allows an attacker to cause Denial of Service or other unspecified impacts.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-33064

почти 3 года назад

An off-by-one error in function wav_read_header in src/wav.c in Libsndfile 1.1.0, results in a write out of bound, which allows an attacker to execute arbitrary code, Denial of Service or other unspecified impacts.

CVSS3: 8.4
EPSS: Низкий
redhat логотип

CVE-2022-3303

около 4 лет назад

A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL pointer dereference while handling the SNDCTL_DSP_SYNC ioctl. A privileged local user (root or member of the audio group) could use this flaw to crash the system, resulting in a denial of service condition

CVSS3: 4.7
EPSS: Низкий
redhat логотип

CVE-2022-32990

больше 4 лет назад

An issue in gimp_layer_invalidate_boundary of GNOME GIMP 2.10.30 allows attackers to trigger an unhandled exception via a crafted XCF file, causing a Denial of Service (DoS).

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-32981

больше 4 лет назад

An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in ptrace PEEKUSER and POKEUSER (aka PEEKUSR and POKEUSR) when accessing floating point registers.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2022-3297

почти 4 года назад

Use After Free in GitHub repository vim/vim prior to 9.0.0579.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-3296

почти 4 года назад

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-3294

почти 4 года назад

Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-apiserver to access endpoints of a Kubelet to establish connections to Pods, retrieve container logs, and more. While Kubernetes already validates the proxying address for Nodes, a bug in kube-apiserver made it possible to bypass this validation. Bypassing this validation could allow authenticated requests destined for Nodes to to the API server's private network.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-3358

OpenSSL supports creating a custom cipher via the legacy EVP_CIPHER_meth_new() function and associated function calls. This function was deprecated in OpenSSL 3.0 and application authors are instead encouraged to use the new provider mechanism in order to implement custom ciphers. OpenSSL versions 3.0.0 to 3.0.5 incorrectly handle legacy custom ciphers passed to the EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2() and EVP_CipherInit_ex2() functions (as well as other similarly named encryption and decryption initialisation functions). Instead of using the custom cipher directly it incorrectly tries to fetch an equivalent cipher from the available providers. An equivalent cipher is found based on the NID passed to EVP_CIPHER_meth_new(). This NID is supposed to represent the unique NID for a given cipher. However it is possible for an application to incorrectly pass NID_undef as this value in the call to EVP_CIPHER_meth_new(). When NID_undef is used in this way the OpenSSL encryption/decry...

CVSS3: 7.5
3%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-3352

Use After Free in GitHub repository vim/vim prior to 9.0.0614.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-3344

A flaw was found in the KVM's AMD nested virtualization (SVM). A malicious L1 guest could purposely fail to intercept the shutdown of a cooperative nested guest (L2), possibly leading to a page fault and kernel panic in the host (L0).

CVSS3: 6.5
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-3324

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-33196

Incorrect default permissions in some memory controller configurations for some Intel(R) Xeon(R) Processors when using Intel(R) Software Guard Extensions which may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-33127

The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a windows environment. This allows attackers to execute arbitrary commands via a crafted string.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-33124

AIOHTTP 3.8.1 can report a "ValueError: Invalid IPv6 URL" outcome, which can lead to a Denial of Service (DoS). NOTE: multiple third parties dispute this issue because there is no example of a context in which denial of service would occur, and many common contexts have exception handing in the calling application

1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-33105

Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-33099

An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.

CVSS3: 6.5
3%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-33082

An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-33070

Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVSS3: 3.1
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-33068

An integer overflow in the component hb-ot-shape-fallback.cc of Harfbuzz v4.3.0 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-33065

Multiple signed integers overflow in function au_read_header in src/au.c and in functions mat4_open and mat4_read_header in src/mat4.c in Libsndfile, allows an attacker to cause Denial of Service or other unspecified impacts.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
redhat логотип
CVE-2022-33064

An off-by-one error in function wav_read_header in src/wav.c in Libsndfile 1.1.0, results in a write out of bound, which allows an attacker to execute arbitrary code, Denial of Service or other unspecified impacts.

CVSS3: 8.4
0%
Низкий
почти 3 года назад
redhat логотип
CVE-2022-3303

A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL pointer dereference while handling the SNDCTL_DSP_SYNC ioctl. A privileged local user (root or member of the audio group) could use this flaw to crash the system, resulting in a denial of service condition

CVSS3: 4.7
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-32990

An issue in gimp_layer_invalidate_boundary of GNOME GIMP 2.10.30 allows attackers to trigger an unhandled exception via a crafted XCF file, causing a Denial of Service (DoS).

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-32981

An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in ptrace PEEKUSER and POKEUSER (aka PEEKUSR and POKEUSR) when accessing floating point registers.

CVSS3: 7.4
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-3297

Use After Free in GitHub repository vim/vim prior to 9.0.0579.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-3296

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-3294

Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-apiserver to access endpoints of a Kubelet to establish connections to Pods, retrieve container logs, and more. While Kubernetes already validates the proxying address for Nodes, a bug in kube-apiserver made it possible to bypass this validation. Bypassing this validation could allow authenticated requests destined for Nodes to to the API server's private network.

CVSS3: 8.8
2%
Низкий
почти 4 года назад

Уязвимостей на страницу