Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 378

Количество 56 378

redhat логотип

CVE-2022-29810

больше 4 лет назад

The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.

CVSS3: 5.1
EPSS: Низкий
redhat логотип

CVE-2022-2980

около 4 лет назад

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0259.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-29800

больше 4 лет назад

A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace scripts that networkd-dispatcher believes to be owned by root with ones that are not.

CVSS3: 4.7
EPSS: Низкий
redhat логотип

CVE-2022-29799

больше 4 лет назад

A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-dispatcher” base directory.

CVSS3: 5.5
EPSS: Средний
redhat логотип

CVE-2022-2978

около 4 лет назад

A flaw use after free in the Linux kernel NILFS file system was found in the way user triggers function security_inode_alloc to fail with following call to function nilfs_mdt_destroy. A local user could use this flaw to crash the system or potentially escalate their privileges on the system.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2022-2977

больше 4 лет назад

A flaw was found in the Linux kernel implementation of proxied virtualized TPM devices. On a system where virtualized TPM devices are configured (this is not the default) a local attacker can create a use-after-free and create a situation where it may be possible to escalate privileges on the system.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-29654

больше 4 лет назад

Buffer overflow vulnerability in quote_for_pmake in asm/nasm.c in nasm before 2.15.05 allows attackers to cause a denial of service via crafted file.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-2964

больше 4 лет назад

A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-2963

около 4 лет назад

A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-2962

около 4 лет назад

A DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descriptor or copies the rx/tx frame, it doesn't check whether the destination address is its own MMIO address. This can cause the device to trigger MMIO handlers multiple times, possibly leading to a stack or heap overflow. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.

CVSS3: 6
EPSS: Низкий
redhat логотип

CVE-2022-2961

около 4 лет назад

A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-2959

больше 4 лет назад

A race condition was found in the Linux kernel's watch queue due to a missing lock in pipe_resize_ring(). The specific flaw exists within the handling of pipe buffers. The issue results from the lack of proper locking when performing operations on an object. This flaw allows a local user to crash the system or escalate their privileges on the system.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2022-29599

больше 6 лет назад

In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-29589

больше 4 лет назад

Crypt Server before 3.3.0 allows XSS in the index view. This is related to serial, computername, and username.

EPSS: Низкий
redhat логотип

CVE-2022-29582

больше 4 лет назад

In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2022-29581

больше 4 лет назад

Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-2953

около 4 лет назад

LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 48d6ece8.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-29526

больше 4 лет назад

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2022-2946

около 4 лет назад

Use After Free in GitHub repository vim/vim prior to 9.0.0246.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-29458

больше 4 лет назад

ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-29810

The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.

CVSS3: 5.1
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2980

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0259.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-29800

A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace scripts that networkd-dispatcher believes to be owned by root with ones that are not.

CVSS3: 4.7
7%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-29799

A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-dispatcher” base directory.

CVSS3: 5.5
12%
Средний
больше 4 лет назад
redhat логотип
CVE-2022-2978

A flaw use after free in the Linux kernel NILFS file system was found in the way user triggers function security_inode_alloc to fail with following call to function nilfs_mdt_destroy. A local user could use this flaw to crash the system or potentially escalate their privileges on the system.

CVSS3: 7
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-2977

A flaw was found in the Linux kernel implementation of proxied virtualized TPM devices. On a system where virtualized TPM devices are configured (this is not the default) a local attacker can create a use-after-free and create a situation where it may be possible to escalate privileges on the system.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-29654

Buffer overflow vulnerability in quote_for_pmake in asm/nasm.c in nasm before 2.15.05 allows attackers to cause a denial of service via crafted file.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2964

A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2963

A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-2962

A DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descriptor or copies the rx/tx frame, it doesn't check whether the destination address is its own MMIO address. This can cause the device to trigger MMIO handlers multiple times, possibly leading to a stack or heap overflow. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.

CVSS3: 6
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-2961

A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-2959

A race condition was found in the Linux kernel's watch queue due to a missing lock in pipe_resize_ring(). The specific flaw exists within the handling of pipe buffers. The issue results from the lack of proper locking when performing operations on an object. This flaw allows a local user to crash the system or escalate their privileges on the system.

CVSS3: 7
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-29599

In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.

CVSS3: 9.8
4%
Низкий
больше 6 лет назад
redhat логотип
CVE-2022-29589

Crypt Server before 3.3.0 allows XSS in the index view. This is related to serial, computername, and username.

1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-29582

In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.

CVSS3: 7
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-29581

Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2953

LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 48d6ece8.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-29526

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

CVSS3: 6.2
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2946

Use After Free in GitHub repository vim/vim prior to 9.0.0246.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-29458

ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу