Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 339

Количество 56 339

redhat логотип

CVE-2022-2000

больше 4 лет назад

Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-1998

больше 4 лет назад

A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2022-1996

больше 4 лет назад

Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2022-1976

около 4 лет назад

A flaw was found in the Linux kernel’s implementation of IO-URING. This flaw allows an attacker with local executable permission to create a string of requests that can cause a use-after-free flaw within the kernel. This issue leads to memory corruption and possible privilege escalation.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-1975

больше 4 лет назад

There is a sleep-in-atomic bug in /net/nfc/netlink.c that allows an attacker to crash the Linux kernel by simulating a nfc device from user-space.

CVSS3: 4.5
EPSS: Низкий
redhat логотип

CVE-2022-1974

больше 4 лет назад

A use-after-free flaw was found in the Linux kernel's NFC core functionality due to a race condition between kobject creation and delete. This vulnerability allows a local attacker with CAP_NET_ADMIN privilege to leak kernel information.

CVSS3: 6.8
EPSS: Низкий
redhat логотип

CVE-2022-1973

больше 4 лет назад

A use-after-free flaw was found in the Linux kernel in log_replay in fs/ntfs3/fslog.c in the NTFS journal. This flaw allows a local attacker to crash the system and leads to a kernel information leak problem.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-1972

больше 4 лет назад

CVE-2022-1972 is duplicate of CVE-2022-2078, so please consider CVE-2022-2078 instead. https://access.redhat.com/security/cve/CVE-2022-2078

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-1970

больше 4 лет назад

[REJECTED CVE] An open redirection vulnerability (open redirect) exists in keycloak auth endpoint. URL can be mentioned as the value of redirect_uri query parameter and it successfully redirects to it.

EPSS: Низкий
redhat логотип

CVE-2022-1968

больше 4 лет назад

Use After Free in GitHub repository vim/vim prior to 8.2.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-1966

больше 4 лет назад

[REJECTED CVE] A use-after-free vulnerability has been identified in the Linux Kernel's netfilter subsystem that did not properly handle the removal of stateful expressions in some situations. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code.

EPSS: Низкий
redhat логотип

CVE-2022-1962

около 4 лет назад

Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-1955

около 4 лет назад

Session 1.13.0 allows an attacker with physical access to the victim's device to bypass the application's password/pin lock to access user data. This is possible due to lack of adequate security controls to prevent dynamic code manipulation.

EPSS: Низкий
redhat логотип

CVE-2022-1949

больше 4 лет назад

An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassword hashes and other sensitive data.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2022-1943

больше 4 лет назад

A flaw out of bounds memory write in the Linux kernel UDF file system functionality was found in the way user triggers some file operation which triggers udf_write_fi(). A local user could use this flaw to crash the system or potentially

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-1942

больше 4 лет назад

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVSS3: 6.6
EPSS: Низкий
redhat логотип

CVE-2022-1941

почти 4 года назад

A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4.21.5 for protobuf-python can lead to out of memory failures. A specially crafted message with multiple key-value per elements creates parsing issues, and can lead to a Denial of Service against services receiving unsanitized input. We recommend upgrading to versions 3.18.3, 3.19.5, 3.20.2, 3.21.6 for protobuf-cpp and 3.18.3, 3.19.5, 3.20.2, 4.21.6 for protobuf-python. Versions for 3.16 and 3.17 are no longer updated.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-1927

больше 4 лет назад

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-1925

больше 4 лет назад

DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_data function which causes a heap overflow. Due to restrictions on chunk sizes in the matroskademux element, the overflow can't be triggered, however the matroskaparse element has no size checks.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-1924

больше 4 лет назад

DOS / potential heap overwrite in mkv demuxing using lzo decompression. Integer overflow in matroskademux element in lzo decompression function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc uses mmap for large chunks, and the OS supports mmap, then it is just a segfault (because the realloc before the integer overflow will use mremap to reduce the size of the chunk, and it will start to write to unmapped memory). However, if using a libc implementation that does not use mmap, or if the OS does not support mmap while using libc, then this could result in a heap overwrite.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-2000

Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-1998

A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system.

CVSS3: 6.4
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-1996

Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.

CVSS3: 9.1
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-1976

A flaw was found in the Linux kernel’s implementation of IO-URING. This flaw allows an attacker with local executable permission to create a string of requests that can cause a use-after-free flaw within the kernel. This issue leads to memory corruption and possible privilege escalation.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-1975

There is a sleep-in-atomic bug in /net/nfc/netlink.c that allows an attacker to crash the Linux kernel by simulating a nfc device from user-space.

CVSS3: 4.5
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-1974

A use-after-free flaw was found in the Linux kernel's NFC core functionality due to a race condition between kobject creation and delete. This vulnerability allows a local attacker with CAP_NET_ADMIN privilege to leak kernel information.

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-1973

A use-after-free flaw was found in the Linux kernel in log_replay in fs/ntfs3/fslog.c in the NTFS journal. This flaw allows a local attacker to crash the system and leads to a kernel information leak problem.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-1972

CVE-2022-1972 is duplicate of CVE-2022-2078, so please consider CVE-2022-2078 instead. https://access.redhat.com/security/cve/CVE-2022-2078

CVSS3: 5.3
больше 4 лет назад
redhat логотип
CVE-2022-1970

[REJECTED CVE] An open redirection vulnerability (open redirect) exists in keycloak auth endpoint. URL can be mentioned as the value of redirect_uri query parameter and it successfully redirects to it.

больше 4 лет назад
redhat логотип
CVE-2022-1968

Use After Free in GitHub repository vim/vim prior to 8.2.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-1966

[REJECTED CVE] A use-after-free vulnerability has been identified in the Linux Kernel's netfilter subsystem that did not properly handle the removal of stateful expressions in some situations. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code.

больше 4 лет назад
redhat логотип
CVE-2022-1962

Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-1955

Session 1.13.0 allows an attacker with physical access to the victim's device to bypass the application's password/pin lock to access user data. This is possible due to lack of adequate security controls to prevent dynamic code manipulation.

0%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-1949

An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassword hashes and other sensitive data.

CVSS3: 7.4
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-1943

A flaw out of bounds memory write in the Linux kernel UDF file system functionality was found in the way user triggers some file operation which triggers udf_write_fi(). A local user could use this flaw to crash the system or potentially

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-1942

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVSS3: 6.6
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-1941

A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4.21.5 for protobuf-python can lead to out of memory failures. A specially crafted message with multiple key-value per elements creates parsing issues, and can lead to a Denial of Service against services receiving unsanitized input. We recommend upgrading to versions 3.18.3, 3.19.5, 3.20.2, 3.21.6 for protobuf-cpp and 3.18.3, 3.19.5, 3.20.2, 4.21.6 for protobuf-python. Versions for 3.16 and 3.17 are no longer updated.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-1927

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-1925

DOS / potential heap overwrite in mkv demuxing using HEADERSTRIP decompression. Integer overflow in matroskaparse element in gst_matroska_decompress_data function which causes a heap overflow. Due to restrictions on chunk sizes in the matroskademux element, the overflow can't be triggered, however the matroskaparse element has no size checks.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-1924

DOS / potential heap overwrite in mkv demuxing using lzo decompression. Integer overflow in matroskademux element in lzo decompression function which causes a segfault, or could cause a heap overwrite, depending on libc and OS. Depending on the libc used, and the underlying OS capabilities, it could be just a segfault or a heap overwrite. If the libc uses mmap for large chunks, and the OS supports mmap, then it is just a segfault (because the realloc before the integer overflow will use mremap to reduce the size of the chunk, and it will start to write to unmapped memory). However, if using a libc implementation that does not use mmap, or if the OS does not support mmap while using libc, then this could result in a heap overwrite.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу