Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 339

Количество 56 339

redhat логотип

CVE-2022-2553

около 4 лет назад

The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-25517

больше 4 лет назад

MyBatis plus v3.4.3 was discovered to contain a SQL injection vulnerability via the Column parameter in /core/conditions/AbstractWrapper.java. NOTE: the vendor's position is that the reported execution of a SQL statement was intended behavior.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-25375

больше 4 лет назад

An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive information from kernel memory.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-25315

больше 4 лет назад

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-25314

больше 4 лет назад

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-25313

больше 4 лет назад

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-25310

больше 4 лет назад

A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the lib/fribidi.c file. This flaw allows an attacker to pass a specially crafted file to Fribidi, leading to a crash and causing a denial of service.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-25309

больше 4 лет назад

A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap-rtl.c file. This flaw allows an attacker to pass a specially crafted file to the Fribidi application with the '--caprtl' option, leading to a crash and causing a denial of service.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-25308

больше 4 лет назад

A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially crafted file to the Fribidi application, which leads to a possible memory leak or a denial of service.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2022-2526

около 4 лет назад

A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-25265

больше 4 лет назад

In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located in supposedly non-executable regions of a file.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-25258

больше 4 лет назад

An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.

CVSS3: 4.6
EPSS: Низкий
redhat логотип

CVE-2022-25255

больше 4 лет назад

In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-25244

больше 4 лет назад

Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-25243

больше 4 лет назад

"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-25236

больше 4 лет назад

xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

CVSS3: 9.8
EPSS: Средний
redhat логотип

CVE-2022-25235

больше 4 лет назад

xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-2522

около 4 лет назад

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0061.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-2521

больше 4 лет назад

It was found in libtiff 4.4.0rc1 that there is an invalid pointer free operation in TIFFClose() at tif_close.c:131 called by tiffcrop.c:2522 that can cause a program crash and denial of service while processing crafted input.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-2520

больше 4 лет назад

A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcrop.c:8621 that can cause program crash when reading a crafted input.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-2553

The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-25517

MyBatis plus v3.4.3 was discovered to contain a SQL injection vulnerability via the Column parameter in /core/conditions/AbstractWrapper.java. NOTE: the vendor's position is that the reported execution of a SQL statement was intended behavior.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-25375

An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive information from kernel memory.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-25315

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-25314

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.

CVSS3: 7.5
5%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-25313

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-25310

A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the lib/fribidi.c file. This flaw allows an attacker to pass a specially crafted file to Fribidi, leading to a crash and causing a denial of service.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-25309

A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap-rtl.c file. This flaw allows an attacker to pass a specially crafted file to the Fribidi application with the '--caprtl' option, leading to a crash and causing a denial of service.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-25308

A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially crafted file to the Fribidi application, which leads to a possible memory leak or a denial of service.

CVSS3: 7
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2526

A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-25265

In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located in supposedly non-executable regions of a file.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-25258

An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.

CVSS3: 4.6
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-25255

In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-25244

Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-25243

"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-25236

xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

CVSS3: 9.8
36%
Средний
больше 4 лет назад
redhat логотип
CVE-2022-25235

xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2522

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0061.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-2521

It was found in libtiff 4.4.0rc1 that there is an invalid pointer free operation in TIFFClose() at tif_close.c:131 called by tiffcrop.c:2522 that can cause a program crash and denial of service while processing crafted input.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2520

A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcrop.c:8621 that can cause program crash when reading a crafted input.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу