Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 339

Количество 56 339

redhat логотип

CVE-2022-26126

больше 4 лет назад

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-26125

больше 4 лет назад

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-26061

около 4 лет назад

A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-2602

почти 4 года назад

io_uring UAF, Unix SCM garbage collection

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2022-2601

почти 4 года назад

A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker may use this vulnerability to circumvent the secure boot mechanism.

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2022-2598

около 4 лет назад

Out-of-bounds Write to API in GitHub repository vim/vim prior to 9.0.0100.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-25972

около 4 лет назад

An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-2596

около 4 лет назад

Inefficient Regular Expression Complexity in GitHub repository node-fetch/node-fetch prior to 3.2.10.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2022-25967

больше 3 лет назад

Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2022-25942

около 4 лет назад

An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-25927

больше 3 лет назад

Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-25914

около 4 лет назад

The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDockerInstalled function, due to attempting to execute input.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-2590

около 4 лет назад

A race condition was found in the way the Linux kernel's memory subsystem handled the copy-on-write (COW) breakage of private read-only shared memory mappings. This flaw allows an unprivileged, local user to gain write access to read-only memory mappings, increasing their privileges on the system.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2022-25901

больше 3 лет назад

Versions of the package cookiejar before 2.1.4 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Cookie.parse function, which uses an insecure regular expression.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-25897

около 4 лет назад

The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-25896

около 4 лет назад

This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2022-2588

около 4 лет назад

It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-25887

около 4 лет назад

The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-25883

около 3 лет назад

Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-25881

больше 3 лет назад

This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-26126

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-26125

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-26061

A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-2602

io_uring UAF, Unix SCM garbage collection

CVSS3: 7
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-2601

A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker may use this vulnerability to circumvent the secure boot mechanism.

CVSS3: 8.2
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-2598

Out-of-bounds Write to API in GitHub repository vim/vim prior to 9.0.0100.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-25972

An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-2596

Inefficient Regular Expression Complexity in GitHub repository node-fetch/node-fetch prior to 3.2.10.

CVSS3: 5.9
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-25967

Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-25942

An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-25927

Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-25914

The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDockerInstalled function, due to attempting to execute input.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-2590

A race condition was found in the way the Linux kernel's memory subsystem handled the copy-on-write (COW) breakage of private read-only shared memory mappings. This flaw allows an unprivileged, local user to gain write access to read-only memory mappings, increasing their privileges on the system.

CVSS3: 7
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-25901

Versions of the package cookiejar before 2.1.4 are vulnerable to Regular Expression Denial of Service (ReDoS) via the Cookie.parse function, which uses an insecure regular expression.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-25897

The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-25896

This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed.

CVSS3: 4.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-2588

It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0.

CVSS3: 7.8
6%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-25887

The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-25883

Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.

CVSS3: 7.5
3%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-25881

This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу