Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 378

Количество 56 378

redhat логотип

CVE-2022-3099

около 4 лет назад

Use After Free in GitHub repository vim/vim prior to 9.0.0360.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-30973

больше 4 лет назад

We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.3.

CVSS3: 3.1
EPSS: Низкий
redhat логотип

CVE-2022-30954

больше 4 лет назад

Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP server.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-30953

больше 4 лет назад

A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.25.3 and earlier allows attackers to connect to an attacker-specified HTTP server.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-30952

больше 4 лет назад

Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to access credentials with attacker-specified IDs stored in the private per-user credentials stores of any attacker-specified user in Jenkins.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-3094

больше 3 лет назад

Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. We are not aware of any cases where this has been exploited. Memory is allocated prior to the checking of access permissions (ACLs) and is retained during the processing of a dynamic update from a client whose access credentials are accepted. Memory allocated to clients that are not permitted to send updates is released immediately upon rejection. The scope of this vulnerability is limited therefore to trusted clients who are permitted to make dynamic zone changes. If a dynamic update is REFUSED, memory will be released again very quickly. Therefore it is only likely to be possible to degrade or stop `named` by sending a flood of unaccepted dynamic updates comparable in magnitude to a query flood intended to achieve the same detrimental outcome. BIND 9.11 and earlier branches are also affected, but through exhaustion of ...

CVSS3: 6.5
EPSS: Средний
redhat логотип

CVE-2022-30948

больше 4 лет назад

Jenkins Mercurial Plugin 2.16 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-30946

больше 4 лет назад

A cross-site request forgery (CSRF) vulnerability in Jenkins Script Security Plugin 1158.v7c1b_73a_69a_08 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-specified webserver.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2022-30945

больше 4 лет назад

Jenkins Pipeline: Groovy Plugin 2689.v434009a_31b_f1 and earlier allows loading any Groovy source files on the classpath of Jenkins and Jenkins plugins in sandboxed pipelines.

CVSS3: 8.5
EPSS: Низкий
redhat логотип

CVE-2022-3080

почти 4 года назад

By sending specific queries to the resolver, an attacker can cause named to crash.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-3078

больше 4 лет назад

An issue was discovered in the Linux kernel through 5.16-rc6. There is a lack of check after calling vzalloc() and lack of free after allocation in drivers/media/test-drivers/vidtv/vidtv_s302m.c.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-30789

больше 4 лет назад

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-30788

больше 4 лет назад

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc in NTFS-3G through 2021.8.22.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-30787

больше 4 лет назад

An integer underflow in fuse_lib_readdir enables arbitrary memory read operations in NTFS-3G through 2021.8.22 when using libfuse-lite.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2022-30786

больше 4 лет назад

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-30785

больше 4 лет назад

A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2022-30784

больше 4 лет назад

A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-30783

больше 4 лет назад

An invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic between NTFS-3G and the kernel in NTFS-3G through 2021.8.22 when using libfuse-lite.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2022-3077

больше 4 лет назад

A buffer overflow vulnerability was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way it handled the I2C_SMBUS_BLOCK_PROC_CALL case (via the ioctl I2C_SMBUS) with malicious input data. This flaw could allow a local user to crash the system.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2022-30704

больше 3 лет назад

Improper initialization in the Intel(R) TXT SINIT ACM for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-3099

Use After Free in GitHub repository vim/vim prior to 9.0.0360.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-30973

We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.3.

CVSS3: 3.1
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30954

Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP server.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30953

A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.25.3 and earlier allows attackers to connect to an attacker-specified HTTP server.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30952

Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to access credentials with attacker-specified IDs stored in the private per-user credentials stores of any attacker-specified user in Jenkins.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-3094

Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. We are not aware of any cases where this has been exploited. Memory is allocated prior to the checking of access permissions (ACLs) and is retained during the processing of a dynamic update from a client whose access credentials are accepted. Memory allocated to clients that are not permitted to send updates is released immediately upon rejection. The scope of this vulnerability is limited therefore to trusted clients who are permitted to make dynamic zone changes. If a dynamic update is REFUSED, memory will be released again very quickly. Therefore it is only likely to be possible to degrade or stop `named` by sending a flood of unaccepted dynamic updates comparable in magnitude to a query flood intended to achieve the same detrimental outcome. BIND 9.11 and earlier branches are also affected, but through exhaustion of ...

CVSS3: 6.5
13%
Средний
больше 3 лет назад
redhat логотип
CVE-2022-30948

Jenkins Mercurial Plugin 2.16 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30946

A cross-site request forgery (CSRF) vulnerability in Jenkins Script Security Plugin 1158.v7c1b_73a_69a_08 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-specified webserver.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30945

Jenkins Pipeline: Groovy Plugin 2689.v434009a_31b_f1 and earlier allows loading any Groovy source files on the classpath of Jenkins and Jenkins plugins in sandboxed pipelines.

CVSS3: 8.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-3080

By sending specific queries to the resolver, an attacker can cause named to crash.

CVSS3: 7.5
2%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-3078

An issue was discovered in the Linux kernel through 5.16-rc6. There is a lack of check after calling vzalloc() and lack of free after allocation in drivers/media/test-drivers/vidtv/vidtv_s302m.c.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30789

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30788

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc in NTFS-3G through 2021.8.22.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30787

An integer underflow in fuse_lib_readdir enables arbitrary memory read operations in NTFS-3G through 2021.8.22 when using libfuse-lite.

CVSS3: 6.7
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30786

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30785

A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.

CVSS3: 6.7
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30784

A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30783

An invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic between NTFS-3G and the kernel in NTFS-3G through 2021.8.22 when using libfuse-lite.

CVSS3: 6.7
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-3077

A buffer overflow vulnerability was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way it handled the I2C_SMBUS_BLOCK_PROC_CALL case (via the ioctl I2C_SMBUS) with malicious input data. This flaw could allow a local user to crash the system.

CVSS3: 6.4
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30704

Improper initialization in the Intel(R) TXT SINIT ACM for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу