Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 339

Количество 56 339

redhat логотип

CVE-2022-2286

около 4 лет назад

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-2285

около 4 лет назад

Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-2284

около 4 лет назад

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-22844

больше 4 лет назад

LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-22827

больше 4 лет назад

storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2022-22826

больше 4 лет назад

nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2022-22825

больше 4 лет назад

lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2022-22824

больше 4 лет назад

defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-22823

больше 4 лет назад

build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-22822

больше 4 лет назад

addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-22818

больше 4 лет назад

The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2022-22817

больше 4 лет назад

PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-22816

больше 4 лет назад

path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-22815

больше 4 лет назад

path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-22764

больше 4 лет назад

Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefox ESR 91.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2022-22763

больше 4 лет назад

When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible. This vulnerability affects Firefox < 96, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2022-22761

больше 4 лет назад

Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2022-22760

больше 4 лет назад

When importing resources using Web Workers, error messages would distinguish the difference between <code>application/javascript</code> responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2022-22759

больше 4 лет назад

If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 9.6
EPSS: Низкий
redhat логотип

CVE-2022-22756

больше 4 лет назад

If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-2286

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-2285

Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-2284

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-22844

LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-22827

storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-22826

nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-22825

lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-22824

defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-22823

build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-22822

addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-22818

The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS.

CVSS3: 6.1
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-22817

PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-22816

path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-22815

path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-22764

Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefox ESR 91.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-22763

When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible. This vulnerability affects Firefox < 96, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-22761

Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-22760

When importing resources using Web Workers, error messages would distinguish the difference between <code>application/javascript</code> responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-22759

If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 9.6
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-22756

If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу