Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 339

Количество 56 339

redhat логотип

CVE-2022-24723

больше 4 лет назад

URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This issue has been patched in version 1.19.9. Removing leading whitespace from values before passing them to URI.parse can be used as a workaround.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-24721

больше 4 лет назад

CometD is a scalable comet implementation for web messaging. In any version prior to 5.0.11, 6.0.6, and 7.0.6, internal usage of Oort and Seti channels is improperly authorized, so any remote user could subscribe and publish to those channels. By subscribing to those channels, a remote user may be able to watch cluster-internal traffic that contains other users' (possibly sensitive) data. By publishing to those channels, a remote user may be able to create/modify/delete other user's data and modify the cluster structure. A fix is available in versions 5.0.11, 6.0.6, and 7.0.6. As a workaround, install a custom `SecurityPolicy` that forbids subscription and publishing to remote, non-Oort, sessions on Oort and Seti channels.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2022-24713

больше 4 лет назад

regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex ...

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2022-2469

около 4 лет назад

GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2022-24675

больше 4 лет назад

encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-2466

около 4 лет назад

It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-24615

больше 4 лет назад

zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result in an application crash. This could be used to mount a denial of service attack against services that use zip4j library.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-24614

больше 4 лет назад

When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an out-of-memory error even for very small inputs. This could be used to mount a denial of service attack against services that use metadata-extractor library.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-24613

больше 4 лет назад

metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which could result in an application crash. This could be used to mount a denial of service attack against services that use metadata-extractor library.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-24599

больше 4 лет назад

In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-2458

около 4 лет назад

XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application's processing of XML data. This attack occurs when XML input containing a reference to an external entity is processed by a weakly configured XML parser. The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. Here, XML external entity injection lead to External Service interaction & Internal file read in Business Central and also Kie-Server APIs.

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2022-2457

около 4 лет назад

A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as the application does not limit the number of unsuccessful login attempts.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-24512

больше 4 лет назад

.NET and Visual Studio Remote Code Execution Vulnerability

CVSS3: 6.3
EPSS: Низкий
redhat логотип

CVE-2022-2447

около 4 лет назад

A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.

CVSS3: 6.6
EPSS: Низкий
redhat логотип

CVE-2022-24464

больше 4 лет назад

.NET and Visual Studio Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-24450

больше 4 лет назад

NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2022-24448

больше 4 лет назад

An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR should occur, but the server instead returns uninitialized data in the file descriptor.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2022-24439

почти 4 года назад

All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-24436

около 4 лет назад

Observable behavioral in power management throttling for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via network access.

CVSS3: 6.3
EPSS: Средний
redhat логотип

CVE-2022-24434

около 5 лет назад

This affects all versions of package dicer. A malicious attacker can send a modified form to server, and crash the nodejs service. An attacker could sent the payload again and again so that the service continuously crashes.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-24723

URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This issue has been patched in version 1.19.9. Removing leading whitespace from values before passing them to URI.parse can be used as a workaround.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-24721

CometD is a scalable comet implementation for web messaging. In any version prior to 5.0.11, 6.0.6, and 7.0.6, internal usage of Oort and Seti channels is improperly authorized, so any remote user could subscribe and publish to those channels. By subscribing to those channels, a remote user may be able to watch cluster-internal traffic that contains other users' (possibly sensitive) data. By publishing to those channels, a remote user may be able to create/modify/delete other user's data and modify the cluster structure. A fix is available in versions 5.0.11, 6.0.6, and 7.0.6. As a workaround, install a custom `SecurityPolicy` that forbids subscription and publishing to remote, non-Oort, sessions on Oort and Seti channels.

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-24713

regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex ...

CVSS3: 7.5
14%
Средний
больше 4 лет назад
redhat логотип
CVE-2022-2469

GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client

CVSS3: 7.1
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-24675

encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.

CVSS3: 7.5
10%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2466

It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.

CVSS3: 5.3
2%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-24615

zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result in an application crash. This could be used to mount a denial of service attack against services that use zip4j library.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-24614

When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of memory that finally leads to an out-of-memory error even for very small inputs. This could be used to mount a denial of service attack against services that use metadata-extractor library.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-24613

metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which could result in an application crash. This could be used to mount a denial of service attack against services that use metadata-extractor library.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-24599

In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2458

XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application's processing of XML data. This attack occurs when XML input containing a reference to an external entity is processed by a weakly configured XML parser. The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. Here, XML external entity injection lead to External Service interaction & Internal file read in Business Central and also Kie-Server APIs.

CVSS3: 8.2
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-2457

A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as the application does not limit the number of unsuccessful login attempts.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-24512

.NET and Visual Studio Remote Code Execution Vulnerability

CVSS3: 6.3
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2447

A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.

CVSS3: 6.6
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-24464

.NET and Visual Studio Denial of Service Vulnerability

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-24450

NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-24448

An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR should occur, but the server instead returns uninitialized data in the file descriptor.

CVSS3: 3.3
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-24439

All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting this vulnerability is possible because the library makes external calls to git without sufficient sanitization of input arguments.

CVSS3: 9.8
5%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-24436

Observable behavioral in power management throttling for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via network access.

CVSS3: 6.3
12%
Средний
около 4 лет назад
redhat логотип
CVE-2022-24434

This affects all versions of package dicer. A malicious attacker can send a modified form to server, and crash the nodejs service. An attacker could sent the payload again and again so that the service continuously crashes.

CVSS3: 7.5
3%
Низкий
около 5 лет назад

Уязвимостей на страницу