Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 378

Количество 56 378

redhat логотип

CVE-2022-32148

около 4 лет назад

Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputil.ReverseProxy.ServeHTTP with a Request.Header map containing a nil value for the X-Forwarded-For header, which causes ReverseProxy to set the client IP as the value of the X-Forwarded-For header.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-3213

около 4 лет назад

A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-32091

около 5 лет назад

MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-32089

около 5 лет назад

MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-32088

около 5 лет назад

MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-32087

около 5 лет назад

MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_args::walk_args.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-32086

около 5 лет назад

MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the component Item_field::fix_outer_field.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-32085

около 5 лет назад

MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-32084

около 5 лет назад

MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-32083

около 5 лет назад

MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cache_tracker.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-32082

около 5 лет назад

MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-32081

около 5 лет назад

MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at /storage/innobase/handler/handler0alter.cc.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-3205

около 4 лет назад

Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection

CVSS3: 4.6
EPSS: Низкий
redhat логотип

CVE-2022-3204

почти 4 года назад

A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegation Attack works by having a malicious delegation with a considerable number of non responsive nameservers. The attack starts by querying a resolver for a record that relies on those unresponsive nameservers. The attack can cause a resolver to spend a lot of time/resources resolving records under a malicious delegation point where a considerable number of unresponsive NS records reside. It can trigger high CPU usage in some resolver implementations that continually look in the cache for resolved NS records in that delegation. This can lead to degraded performance and eventually denial of service in orchestrated attacks. Unbound does not suffer from high CPU usage, but resources are still needed for resolving the malicious delegation. Unbound will keep trying to resolve the record until hard limits are reached. Based on the nature of the a...

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-3202

больше 4 лет назад

A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This could allow a local attacker to crash the system or leak kernel internal information.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2022-3193

почти 4 года назад

An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "error_description" fails to sanitize the entry, allowing the vulnerability to trigger on the Windows Service Accounts home pages.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-3190

почти 4 года назад

Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0 to 3.4.15 allows denial of service via packet injection or crafted capture file

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-31813

больше 4 лет назад

Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2022-31783

больше 4 лет назад

Liblouis 3.21.0 has an out-of-bounds write in compileRule in compileTranslationTable.c, as demonstrated by lou_trace.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2022-31777

почти 4 года назад

A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-32148

Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputil.ReverseProxy.ServeHTTP with a Request.Header map containing a nil value for the X-Forwarded-For header, which causes ReverseProxy to set the client IP as the value of the X-Forwarded-For header.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-3213

A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-32091

MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.

CVSS3: 6.5
2%
Низкий
около 5 лет назад
redhat логотип
CVE-2022-32089

MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.

CVSS3: 6.5
2%
Низкий
около 5 лет назад
redhat логотип
CVE-2022-32088

MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort.

CVSS3: 6.5
2%
Низкий
около 5 лет назад
redhat логотип
CVE-2022-32087

MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_args::walk_args.

CVSS3: 6.5
2%
Низкий
около 5 лет назад
redhat логотип
CVE-2022-32086

MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the component Item_field::fix_outer_field.

CVSS3: 6.5
1%
Низкий
около 5 лет назад
redhat логотип
CVE-2022-32085

MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor.

CVSS3: 6.5
2%
Низкий
около 5 лет назад
redhat логотип
CVE-2022-32084

MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select.

CVSS3: 6.5
2%
Низкий
около 5 лет назад
redhat логотип
CVE-2022-32083

MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cache_tracker.

CVSS3: 6.5
2%
Низкий
около 5 лет назад
redhat логотип
CVE-2022-32082

MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.

CVSS3: 6.5
2%
Низкий
около 5 лет назад
redhat логотип
CVE-2022-32081

MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at /storage/innobase/handler/handler0alter.cc.

CVSS3: 6.5
2%
Низкий
около 5 лет назад
redhat логотип
CVE-2022-3205

Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection

CVSS3: 4.6
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-3204

A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegation Attack works by having a malicious delegation with a considerable number of non responsive nameservers. The attack starts by querying a resolver for a record that relies on those unresponsive nameservers. The attack can cause a resolver to spend a lot of time/resources resolving records under a malicious delegation point where a considerable number of unresponsive NS records reside. It can trigger high CPU usage in some resolver implementations that continually look in the cache for resolved NS records in that delegation. This can lead to degraded performance and eventually denial of service in orchestrated attacks. Unbound does not suffer from high CPU usage, but resources are still needed for resolving the malicious delegation. Unbound will keep trying to resolve the record until hard limits are reached. Based on the nature of the a...

CVSS3: 7.5
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-3202

A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This could allow a local attacker to crash the system or leak kernel internal information.

CVSS3: 7.1
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-3193

An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "error_description" fails to sanitize the entry, allowing the vulnerability to trigger on the Windows Service Accounts home pages.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-3190

Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0 to 3.4.15 allows denial of service via packet injection or crafted capture file

CVSS3: 5.5
2%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-31813

Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.

CVSS3: 7.3
4%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-31783

Liblouis 3.21.0 has an out-of-bounds write in compileRule in compileTranslationTable.c, as demonstrated by lou_trace.

CVSS3: 6.2
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-31777

A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.

CVSS3: 5.4
2%
Низкий
почти 4 года назад

Уязвимостей на страницу