Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 339

Количество 56 339

redhat логотип

CVE-2022-25878

больше 4 лет назад

The package protobufjs before 6.11.3 are vulnerable to Prototype Pollution which can allow an attacker to add/modify properties of the Object.prototype. This vulnerability can occur in multiple ways: 1. by providing untrusted user input to util.setProperty or to ReflectionObject.setParsedOption functions 2. by parsing/loading .proto files

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2022-2586

около 4 лет назад

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

CVSS3: 6.7
EPSS: Средний
redhat логотип

CVE-2022-25869

около 4 лет назад

All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of <textarea> elements.

CVSS3: 4.2
EPSS: Низкий
redhat логотип

CVE-2022-2585

около 4 лет назад

It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-25858

около 4 лет назад

The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-25857

около 4 лет назад

The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-25853

больше 3 лет назад

All versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to improper input sanitization.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2022-25845

около 4 лет назад

The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).

CVSS3: 8.1
EPSS: Средний
redhat логотип

CVE-2022-25844

больше 4 лет назад

The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value. **Note:** 1) This package has been deprecated and is no longer maintained. 2) The vulnerable versions are 1.7.0 and higher.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-2581

около 4 лет назад

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0104.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-2580

около 4 лет назад

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0102.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-25762

больше 4 лет назад

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2022-25758

около 4 лет назад

All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-2571

около 4 лет назад

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0101.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-2568

около 4 лет назад

A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove the superuser privileges.

CVSS3: 7.2
EPSS: Низкий
redhat логотип

CVE-2022-25648

больше 4 лет назад

The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-25647

больше 4 лет назад

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2022-25645

больше 4 лет назад

All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-25636

больше 4 лет назад

net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nf_tables_offload.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-25634

больше 4 лет назад

Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-25878

The package protobufjs before 6.11.3 are vulnerable to Prototype Pollution which can allow an attacker to add/modify properties of the Object.prototype. This vulnerability can occur in multiple ways: 1. by providing untrusted user input to util.setProperty or to ReflectionObject.setParsedOption functions 2. by parsing/loading .proto files

CVSS3: 8.2
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2586

It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.

CVSS3: 6.7
10%
Средний
около 4 лет назад
redhat логотип
CVE-2022-25869

All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of <textarea> elements.

CVSS3: 4.2
7%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-2585

It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-25858

The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-25857

The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-25853

All versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to improper input sanitization.

CVSS3: 7.4
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-25845

The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If upgrading is not possible, you can enable [safeMode](https://github.com/alibaba/fastjson/wiki/fastjson_safemode).

CVSS3: 8.1
19%
Средний
около 4 лет назад
redhat логотип
CVE-2022-25844

The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value. **Note:** 1) This package has been deprecated and is no longer maintained. 2) The vulnerable versions are 1.7.0 and higher.

CVSS3: 7.5
5%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2581

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0104.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-2580

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0102.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-25762

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.

CVSS3: 8.6
8%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-25758

All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.

CVSS3: 5.3
2%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-2571

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0101.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-2568

A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove the superuser privileges.

CVSS3: 7.2
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-25648

The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-25647

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

CVSS3: 7.5
12%
Средний
больше 4 лет назад
redhat логотип
CVE-2022-25645

All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-25636

net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nf_tables_offload.

CVSS3: 7.8
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-25634

Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.

CVSS3: 3.3
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу