Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 378

Количество 56 378

redhat логотип

CVE-2022-28286

больше 4 лет назад

Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2022-28285

больше 4 лет назад

When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjunction with another vulnerability this could have been used for an out of bounds memory read. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2022-28282

больше 4 лет назад

By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object during JavaScript execution and then referencing the object through a freed pointer, leading to a potential exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2022-28281

больше 4 лет назад

If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent process, an out of bounds write would have occurred leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2022-28202

больше 4 лет назад

An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2022-2819

около 4 лет назад

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-28199

около 4 лет назад

NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-2817

около 4 лет назад

Use After Free in GitHub repository vim/vim prior to 9.0.0213.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-2816

около 4 лет назад

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-28131

около 4 лет назад

Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2022-28109

больше 4 лет назад

Selenium Selenium Grid (formerly Selenium Standalone Server) Fixed in 4.0.0-alpha-7 is affected by: DNS rebinding. The impact is: execute arbitrary code (remote). The component is: WebDriver endpoint of Selenium Grid / Selenium Standalone Server. The attack vector is: Triggered by browsing to to a malicious remote web server. The WebDriver endpoint of Selenium Server (Grid) is vulnerable to DNS rebinding. This can be used to execute arbitrary code on the machine.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2022-2806

больше 4 лет назад

It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev

CVSS3: 5.1
EPSS: Низкий
redhat логотип

CVE-2022-2805

больше 4 лет назад

A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allows an attacker with sufficient privileges to read the log file, leading to confidentiality loss.

CVSS3: 5.1
EPSS: Низкий
redhat логотип

CVE-2022-28048

больше 4 лет назад

STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2022-28042

больше 4 лет назад

stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2022-28041

больше 4 лет назад

stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2022-2795

почти 4 года назад

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-27950

больше 4 лет назад

In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exists for a certain hid_parse error condition.

CVSS3: 5.1
EPSS: Низкий
redhat логотип

CVE-2022-27943

больше 4 лет назад

libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-2785

около 4 лет назад

There exists an arbitrary memory read within the Linux Kernel BPF - Constants provided to fill pointers in structs passed in to bpf_sys_bpf are not verified and can point anywhere, including memory not owned by BPF. An attacker with CAP_BPF can arbitrarily read memory from anywhere on the system. We recommend upgrading past commit 86f44fcec22c

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-28286

Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-28285

When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjunction with another vulnerability this could have been used for an out of bounds memory read. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-28282

By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object during JavaScript execution and then referencing the object through a freed pointer, leading to a potential exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-28281

If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent process, an out of bounds write would have occurred leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-28202

An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2819

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-28199

NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-2817

Use After Free in GitHub repository vim/vim prior to 9.0.0213.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-2816

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-28131

Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.

CVSS3: 7.3
2%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-28109

Selenium Selenium Grid (formerly Selenium Standalone Server) Fixed in 4.0.0-alpha-7 is affected by: DNS rebinding. The impact is: execute arbitrary code (remote). The component is: WebDriver endpoint of Selenium Grid / Selenium Standalone Server. The attack vector is: Triggered by browsing to to a malicious remote web server. The WebDriver endpoint of Selenium Server (Grid) is vulnerable to DNS rebinding. This can be used to execute arbitrary code on the machine.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2806

It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev

CVSS3: 5.1
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2805

A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allows an attacker with sufficient privileges to read the log file, leading to confidentiality loss.

CVSS3: 5.1
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-28048

STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.

CVSS3: 7.3
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-28042

stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode.

CVSS3: 7.3
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-28041

stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

CVSS3: 6.2
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2795

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

CVSS3: 5.3
2%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-27950

In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exists for a certain hid_parse error condition.

CVSS3: 5.1
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-27943

libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2785

There exists an arbitrary memory read within the Linux Kernel BPF - Constants provided to fill pointers in structs passed in to bpf_sys_bpf are not verified and can point anywhere, including memory not owned by BPF. An attacker with CAP_BPF can arbitrarily read memory from anywhere on the system. We recommend upgrading past commit 86f44fcec22c

CVSS3: 4.4
0%
Низкий
около 4 лет назад

Уязвимостей на страницу