Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 378

Количество 56 378

redhat логотип

CVE-2022-32742

около 4 лет назад

A flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enough data to fulfill the write, allowing server memory contents to be written into the file (or printer) instead of client-supplied data. The client cannot control the area of the server memory written to the file (or printer).

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2022-3266

почти 4 года назад

An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-3262

почти 4 года назад

A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2022-3261

почти 4 года назад

A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive information problem.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-3260

около 4 лет назад

The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-3259

около 4 лет назад

Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2022-3256

почти 4 года назад

Use After Free in GitHub repository vim/vim prior to 9.0.0530.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-32549

около 4 лет назад

Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-32547

больше 4 лет назад

In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', which requires 4 byte alignment at MagickCore/property.c. Whenever crafted or untrusted input is processed by ImageMagick, this causes a negative impact to application availability or other problems related to undefined behavior.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-32546

больше 4 лет назад

A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2022-32545

больше 4 лет назад

A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned char' at coders/psd.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2022-32532

около 4 лет назад

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 8.1
EPSS: Средний
redhat логотип

CVE-2022-3248

почти 3 года назад

A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the boundaries, as permissions will not be applied.

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2022-3239

больше 4 лет назад

A flaw use after free in the Linux kernel video4linux driver was found in the way user triggers em28xx_usb_probe() for the Empia 28xx based TV cards. A local user could use this flaw to crash the system or potentially escalate their privileges on the system.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2022-3238

почти 4 года назад

A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2022-3235

почти 4 года назад

Use After Free in GitHub repository vim/vim prior to 9.0.0490.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-3234

почти 4 года назад

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-32323

около 4 лет назад

AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2022-32296

больше 4 лет назад

The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056.

EPSS: Низкий
redhat логотип

CVE-2022-32287

почти 4 года назад

A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files outside the designated target directory using carefully crafted ZIP entry names. This issue affects Apache UIMA Apache UIMA version 3.3.0 and prior versions. Note that PEAR files should never be installed into an UIMA installation from untrusted sources because PEAR archives are executable plugins that will be able to perform any actions with the same privileges as the host Java Virtual Machine.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-32742

A flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enough data to fulfill the write, allowing server memory contents to be written into the file (or printer) instead of client-supplied data. The client cannot control the area of the server memory written to the file (or printer).

CVSS3: 4.3
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-3266

An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-3262

A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.

CVSS3: 8.1
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-3261

A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive information problem.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-3260

The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-3259

Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks.

CVSS3: 7.4
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-3256

Use After Free in GitHub repository vim/vim prior to 9.0.0530.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-32549

Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.

CVSS3: 5.3
2%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-32547

In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', which requires 4 byte alignment at MagickCore/property.c. Whenever crafted or untrusted input is processed by ImageMagick, this causes a negative impact to application availability or other problems related to undefined behavior.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-32546

A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.

CVSS3: 3.3
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-32545

A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned char' at coders/psd.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.

CVSS3: 3.3
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-32532

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVSS3: 8.1
27%
Средний
около 4 лет назад
redhat логотип
CVE-2022-3248

A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the boundaries, as permissions will not be applied.

CVSS3: 4.4
0%
Низкий
почти 3 года назад
redhat логотип
CVE-2022-3239

A flaw use after free in the Linux kernel video4linux driver was found in the way user triggers em28xx_usb_probe() for the Empia 28xx based TV cards. A local user could use this flaw to crash the system or potentially escalate their privileges on the system.

CVSS3: 7
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-3238

A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVSS3: 6.4
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-3235

Use After Free in GitHub repository vim/vim prior to 9.0.0490.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-3234

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-32323

AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660.

CVSS3: 7.3
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-32296

The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056.

0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-32287

A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files outside the designated target directory using carefully crafted ZIP entry names. This issue affects Apache UIMA Apache UIMA version 3.3.0 and prior versions. Note that PEAR files should never be installed into an UIMA installation from untrusted sources because PEAR archives are executable plugins that will be able to perform any actions with the same privileges as the host Java Virtual Machine.

CVSS3: 7.5
2%
Низкий
почти 4 года назад

Уязвимостей на страницу