Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 322

Количество 56 322

redhat логотип

CVE-2022-0714

больше 4 лет назад

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.

CVSS3: 5.5
EPSS: Средний
redhat логотип

CVE-2022-0711

больше 4 лет назад

A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2022-0708

больше 4 лет назад

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2022-0696

больше 4 лет назад

NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-0691

больше 4 лет назад

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-0686

больше 4 лет назад

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2022-0685

больше 4 лет назад

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-0675

больше 4 лет назад

In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unmanaged rules to exist on the target system and leave the system in an unsafe state.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2022-0670

около 4 лет назад

A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2022-0669

больше 4 лет назад

A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-0667

больше 4 лет назад

When the vulnerability is triggered the BIND process will exit. BIND 9.18.0

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-0646

больше 4 лет назад

A flaw use after free in the Linux kernel Management Component Transport Protocol (MCTP) subsystem was found in the way user triggers cancel_work_sync after the unregister_netdev during removing device. A local user could use this flaw to crash the system or escalate their privileges on the system. It is actual from Linux Kernel 5.17-rc1 (when mctp-serial.c introduced) till 5.17-rc5.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2022-0644

почти 5 лет назад

A vulnerability was found in the Linux kernel’s kernel_read_file_from_fd in the filesystem. This flaw allows a local user with normal privileges, to impact the availability of the system when attempting to read a file without read access/permission.

EPSS: Низкий
redhat логотип

CVE-2022-0639

больше 4 лет назад

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2022-0635

больше 4 лет назад

Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-0629

больше 4 лет назад

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-0617

больше 4 лет назад

A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc1 till 5.17-rc2.

CVSS3: 4.7
EPSS: Низкий
redhat логотип

CVE-2022-0613

больше 4 лет назад

Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-0586

больше 4 лет назад

Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-0585

больше 4 лет назад

Large loops in multiple protocol dissectors in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allow denial of service via packet injection or crafted capture file

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-0714

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.

CVSS3: 5.5
13%
Средний
больше 4 лет назад
redhat логотип
CVE-2022-0711

A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.

CVSS3: 7.5
17%
Средний
больше 4 лет назад
redhat логотип
CVE-2022-0708

Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-0696

NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.

CVSS3: 5.5
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-0691

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-0686

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.

CVSS3: 9.1
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-0685

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-0675

In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unmanaged rules to exist on the target system and leave the system in an unsafe state.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-0670

A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.

CVSS3: 8.1
1%
Низкий
около 4 лет назад
redhat логотип
CVE-2022-0669

A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-0667

When the vulnerability is triggered the BIND process will exit. BIND 9.18.0

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-0646

A flaw use after free in the Linux kernel Management Component Transport Protocol (MCTP) subsystem was found in the way user triggers cancel_work_sync after the unregister_netdev during removing device. A local user could use this flaw to crash the system or escalate their privileges on the system. It is actual from Linux Kernel 5.17-rc1 (when mctp-serial.c introduced) till 5.17-rc5.

CVSS3: 6.4
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-0644

A vulnerability was found in the Linux kernel’s kernel_read_file_from_fd in the filesystem. This flaw allows a local user with normal privileges, to impact the availability of the system when attempting to read a file without read access/permission.

почти 5 лет назад
redhat логотип
CVE-2022-0639

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.

CVSS3: 6.2
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-0635

Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-0629

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-0617

A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc1 till 5.17-rc2.

CVSS3: 4.7
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-0613

Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-0586

Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-0585

Large loops in multiple protocol dissectors in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allow denial of service via packet injection or crafted capture file

CVSS3: 7.5
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу