Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 378

Количество 56 378

redhat логотип

CVE-2022-3033

около 4 лет назад

If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag having the <code>http-equiv="refresh"</code> attribute, and the content attribute specifying an URL, then Thunderbird started a network request to that URL, regardless of the configuration to block remote content. In combination with certain other HTML elements and attributes in the email, it was possible to execute JavaScript code included in the message in the context of the message compose document. The JavaScript code was able to perform actions including, but probably not limited to, read and modify the contents of the message compose document, including the quoted original message, which could potentially contain the decrypted plaintext of encrypted data in the crafted email. The contents could then be transmitted to the network, either to the URL specified in the META refresh tag, or to a different URL, as the JavaScript code could modify the URL specified ...

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-30339

больше 3 лет назад

Out-of-bounds read in firmware for the Intel(R) Integrated Sensor Solution before versions 5.4.2.4579v3, 5.4.1.4479 and 5.0.0.4143 may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 6
EPSS: Низкий
redhat логотип

CVE-2022-3032

около 4 лет назад

When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2022-30323

больше 4 лет назад

go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2022-30322

больше 4 лет назад

go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP responses. Fixed in 1.6.1 and 2.1.0.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2022-30321

больше 4 лет назад

go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2022-30294

больше 4 лет назад

[REJECTED CVE] In WebKitGTK through 2.36.0 (and WPE WebKit), there is a use-after-free in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.

EPSS: Низкий
redhat логотип

CVE-2022-30293

больше 4 лет назад

In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-3028

около 4 лет назад

A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2022-30184

около 4 лет назад

.NET and Visual Studio Information Disclosure Vulnerability

CVSS3: 5
EPSS: Низкий
redhat логотип

CVE-2022-3016

около 4 лет назад

Use After Free in GitHub repository vim/vim prior to 9.0.0286.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-30126

больше 4 лет назад

In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0

CVSS3: 3.1
EPSS: Низкий
redhat логотип

CVE-2022-30123

больше 4 лет назад

A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.

CVSS3: 10
EPSS: Низкий
redhat логотип

CVE-2022-30122

больше 4 лет назад

A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-30115

больше 4 лет назад

Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by having the trailing dot in the HSTS cache and *not* using thetrailing dot in the URL.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-30067

больше 4 лет назад

GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of memory, resulting in insufficient memory or program crash.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2022-30065

больше 4 лет назад

A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2022-30045

около 4 лет назад

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling while parsing crafted XML files, leading to a heap out-of-bounds read.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-29970

больше 4 лет назад

Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-2996

больше 4 лет назад

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-3033

If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag having the <code>http-equiv="refresh"</code> attribute, and the content attribute specifying an URL, then Thunderbird started a network request to that URL, regardless of the configuration to block remote content. In combination with certain other HTML elements and attributes in the email, it was possible to execute JavaScript code included in the message in the context of the message compose document. The JavaScript code was able to perform actions including, but probably not limited to, read and modify the contents of the message compose document, including the quoted original message, which could potentially contain the decrypted plaintext of encrypted data in the crafted email. The contents could then be transmitted to the network, either to the URL specified in the META refresh tag, or to a different URL, as the JavaScript code could modify the URL specified ...

CVSS3: 7.5
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-30339

Out-of-bounds read in firmware for the Intel(R) Integrated Sensor Solution before versions 5.4.2.4579v3, 5.4.1.4479 and 5.0.0.4143 may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 6
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-3032

When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remote objects specified in the nested document, for example images or videos, were not blocked. Rather, the network was accessed, the objects were loaded and displayed. This vulnerability affects Thunderbird < 102.2.1 and Thunderbird < 91.13.1.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-30323

go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.

CVSS3: 8.6
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30322

go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP responses. Fixed in 1.6.1 and 2.1.0.

CVSS3: 8.6
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30321

go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0.

CVSS3: 8.6
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30294

[REJECTED CVE] In WebKitGTK through 2.36.0 (and WPE WebKit), there is a use-after-free in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.

больше 4 лет назад
redhat логотип
CVE-2022-30293

In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-3028

A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket.

CVSS3: 6.7
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-30184

.NET and Visual Studio Information Disclosure Vulnerability

CVSS3: 5
6%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-3016

Use After Free in GitHub repository vim/vim prior to 9.0.0286.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-30126

In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0

CVSS3: 3.1
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30123

A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.

CVSS3: 10
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30122

A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30115

Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given URL used atrailing dot while not using one when it built the HSTS cache. Or the otherway around - by having the trailing dot in the HSTS cache and *not* using thetrailing dot in the URL.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30067

GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a huge amount of memory, resulting in insufficient memory or program crash.

CVSS3: 6.2
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30065

A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.

CVSS3: 6.2
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-30045

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling while parsing crafted XML files, leading to a heap out-of-bounds read.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-29970

Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2996

A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks.

CVSS3: 7.4
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу