Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 378

Количество 56 378

redhat логотип

CVE-2022-2849

около 4 лет назад

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220.

CVSS3: 2.8
EPSS: Низкий
redhat логотип

CVE-2022-28487

больше 4 лет назад

Tcpreplay version 4.4.1 contains a memory leakage flaw in fix_ipv6_checksums() function. The highest threat from this vulnerability is to data confidentiality.

EPSS: Низкий
redhat логотип

CVE-2022-28463

больше 4 лет назад

ImageMagick 7.1.0-27 is vulnerable to Buffer Overflow.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-2845

около 4 лет назад

Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218.

CVSS3: 2.8
EPSS: Низкий
redhat логотип

CVE-2022-28391

больше 4 лет назад

BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-28390

больше 4 лет назад

ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2022-28389

больше 4 лет назад

mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-28388

больше 4 лет назад

usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-2837

около 4 лет назад

A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2022-2835

около 4 лет назад

A flaw was found in coreDNS. This flaw allows a malicious user to reroute internal calls to some internal services that were accessed by the FQDN in a format of <service>.<namespace>.svc.

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2022-28356

больше 4 лет назад

In the Linux kernel before 5.17.1, a refcount leak bug was found in net/llc/af_llc.c.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-28347

больше 4 лет назад

A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name.

CVSS3: 9.4
EPSS: Низкий
redhat логотип

CVE-2022-28346

больше 4 лет назад

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.

CVSS3: 9.4
EPSS: Средний
redhat логотип

CVE-2022-28331

больше 3 лет назад

On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-28330

больше 4 лет назад

Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-2832

около 4 лет назад

A flaw was found in Blender 3.3.0. A null pointer dereference exists in source/blender/gpu/opengl/gl_backend.cc that may lead to loss of confidentiality and integrity.

CVSS3: 5.1
EPSS: Низкий
redhat логотип

CVE-2022-28327

больше 4 лет назад

The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-28323

больше 4 лет назад

An issue was discovered in MediaWiki through 1.37.2. The SecurePoll extension allows a leak because sorting by timestamp is supported,

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-28321

почти 4 года назад

The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from an IP address that is not resolvable via DNS. In such conditions, a user with denied access to a machine can still get access. NOTE: the relevance of this issue is largely limited to openSUSE Tumbleweed and openSUSE Factory; it does not affect Linux-PAM upstream.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-28289

больше 4 лет назад

Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 91.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-2849

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220.

CVSS3: 2.8
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-28487

Tcpreplay version 4.4.1 contains a memory leakage flaw in fix_ipv6_checksums() function. The highest threat from this vulnerability is to data confidentiality.

2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-28463

ImageMagick 7.1.0-27 is vulnerable to Buffer Overflow.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2845

Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218.

CVSS3: 2.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-28391

BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-28390

ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.

CVSS3: 7
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-28389

mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-28388

usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2837

A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-2835

A flaw was found in coreDNS. This flaw allows a malicious user to reroute internal calls to some internal services that were accessed by the FQDN in a format of <service>.<namespace>.svc.

CVSS3: 4.4
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-28356

In the Linux kernel before 5.17.1, a refcount leak bug was found in net/llc/af_llc.c.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-28347

A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name.

CVSS3: 9.4
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-28346

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.

CVSS3: 9.4
19%
Средний
больше 4 лет назад
redhat логотип
CVE-2022-28331

On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-28330

Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.

CVSS3: 5.3
4%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2832

A flaw was found in Blender 3.3.0. A null pointer dereference exists in source/blender/gpu/opengl/gl_backend.cc that may lead to loss of confidentiality and integrity.

CVSS3: 5.1
2%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-28327

The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-28323

An issue was discovered in MediaWiki through 1.37.2. The SecurePoll extension allows a leak because sorting by timestamp is supported,

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-28321

The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from an IP address that is not resolvable via DNS. In such conditions, a user with denied access to a machine can still get access. NOTE: the relevance of this issue is largely limited to openSUSE Tumbleweed and openSUSE Factory; it does not affect Linux-PAM upstream.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-28289

Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 91.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу