Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 339

Количество 56 339

redhat логотип

CVE-2022-23913

больше 4 лет назад

In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-2385

около 4 лет назад

A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2022-23852

больше 4 лет назад

Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-23837

больше 4 лет назад

In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-23833

больше 4 лет назад

An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2022-23829

около 2 лет назад

A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode (SMM) ROM protections.

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2022-23825

около 4 лет назад

Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.

CVSS3: 5.6
EPSS: Низкий
redhat логотип

CVE-2022-23824

около 4 лет назад

IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.

CVSS3: 5.6
EPSS: Низкий
redhat логотип

CVE-2022-23823

около 4 лет назад

A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.

CVSS3: 6.3
EPSS: Низкий
redhat логотип

CVE-2022-23816

около 4 лет назад

A flaw was found in hw. Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.

CVSS3: 5.6
EPSS: Низкий
redhat логотип

CVE-2022-23814

почти 4 года назад

Failure to validate addresses provided by software to BIOS commands may result in a potential loss of integrity of guest memory in a confidential compute environment.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-23813

почти 4 года назад

The software interfaces to ASP and SMU may not enforce the SNP memory security policy resulting in a potential loss of integrity of guest memory in a confidential compute environment.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-2380

больше 4 лет назад

The Linux kernel was found vulnerable out of bounds memory access in the drivers/video/fbdev/sm712fb.c:smtcfb_read() function. The vulnerability could result in local attackers being able to crash the kernel.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2022-23806

больше 4 лет назад

Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2022-23773

больше 4 лет назад

cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-23772

больше 4 лет назад

Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-23713

около 4 лет назад

A cross-site-scripting (XSS) vulnerability was discovered in the Vega Charts Kibana integration which could allow arbitrary JavaScript to be executed in a victim’s browser.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2022-23712

больше 4 лет назад

A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-23711

больше 4 лет назад

A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack monitoring features provide a way to keep a pulse on the health and performance of your Elasticsearch cluster. Authentication with a vulnerable Kibana instance is not required to view the exposed information. The Elastic Stack monitoring exposure only impacts users that have set any of the optional monitoring.ui.elasticsearch.* settings in order to configure Kibana as a remote UI for Elastic Stack Monitoring. The same vulnerability in Kibana could expose other non-sensitive application-internal information in the page source.

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2022-23710

больше 4 лет назад

A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow arbitrary JavaScript to be executed in a victim’s browser.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-23913

In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-2385

A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.

CVSS3: 8.1
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-23852

Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-23837

In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.

CVSS3: 7.5
5%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-23833

An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.

CVSS3: 7.5
50%
Средний
больше 4 лет назад
redhat логотип
CVE-2022-23829

A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode (SMM) ROM protections.

CVSS3: 8.2
0%
Низкий
около 2 лет назад
redhat логотип
CVE-2022-23825

Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.

CVSS3: 5.6
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-23824

IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.

CVSS3: 5.6
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-23823

A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.

CVSS3: 6.3
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-23816

A flaw was found in hw. Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.

CVSS3: 5.6
около 4 лет назад
redhat логотип
CVE-2022-23814

Failure to validate addresses provided by software to BIOS commands may result in a potential loss of integrity of guest memory in a confidential compute environment.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-23813

The software interfaces to ASP and SMU may not enforce the SNP memory security policy resulting in a potential loss of integrity of guest memory in a confidential compute environment.

CVSS3: 5.3
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-2380

The Linux kernel was found vulnerable out of bounds memory access in the drivers/video/fbdev/sm712fb.c:smtcfb_read() function. The vulnerability could result in local attackers being able to crash the kernel.

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-23806

Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.

CVSS3: 7.1
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-23773

cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-23772

Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-23713

A cross-site-scripting (XSS) vulnerability was discovered in the Vega Charts Kibana integration which could allow arbitrary JavaScript to be executed in a victim’s browser.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-23712

A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.

CVSS3: 7.5
7%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-23711

A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack monitoring features provide a way to keep a pulse on the health and performance of your Elasticsearch cluster. Authentication with a vulnerable Kibana instance is not required to view the exposed information. The Elastic Stack monitoring exposure only impacts users that have set any of the optional monitoring.ui.elasticsearch.* settings in order to configure Kibana as a remote UI for Elastic Stack Monitoring. The same vulnerability in Kibana could expose other non-sensitive application-internal information in the page source.

CVSS3: 8.2
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-23710

A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow arbitrary JavaScript to be executed in a victim’s browser.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу