Количество 56 322
Количество 56 322
CVE-2022-0492
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
CVE-2022-0487
A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidentiality. This flaw affects kernel versions prior to 5.14 rc1.
CVE-2022-0485
A flaw was found in the copying tool `nbdcopy` of libnbd. When performing multi-threaded copies using asynchronous nbd calls, nbdcopy was blindly treating the completion of an asynchronous command as successful, rather than checking the *error parameter. This could result in the silent creation of a corrupted destination image.
CVE-2022-0480
A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can lead to host memory exhaustion due to memcg not limiting the number of Portable Operating System Interface (POSIX) file locks.
CVE-2022-0443
Use After Free in GitHub repository vim/vim prior to 8.2.
CVE-2022-0435
A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network.
CVE-2022-0433
A NULL pointer dereference flaw was found in the Linux kernel's BPF subsystem in the way a user triggers the map_get_next_key function of the BPF bloom filter. This flaw allows a local user to crash the system. This flaw affects Linux kernel versions prior to 5.17-rc1.
CVE-2022-0417
Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.
CVE-2022-0413
Use After Free in GitHub repository vim/vim prior to 8.2.
CVE-2022-0408
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVE-2022-0407
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVE-2022-0400
An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos.
CVE-2022-0396
BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSE_WAIT status for an indefinite period of time, even after the client has terminated the connection.
CVE-2022-0393
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
CVE-2022-0392
Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.
CVE-2022-0391
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.
CVE-2022-0382
An information leak flaw was found due to uninitialized memory in the Linux kernel's TIPC protocol subsystem, in the way a user sends a TIPC datagram to one or more destinations. This flaw allows a local user to read some kernel memory. This issue is limited to no more than 7 bytes, and the user cannot control what is read. This flaw affects the Linux kernel versions prior to 5.17-rc1.
CVE-2022-0368
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
CVE-2022-0361
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVE-2022-0359
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-0492 A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly. | CVSS3: 7 | 6% Низкий | больше 4 лет назад | |
CVE-2022-0487 A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidentiality. This flaw affects kernel versions prior to 5.14 rc1. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2022-0485 A flaw was found in the copying tool `nbdcopy` of libnbd. When performing multi-threaded copies using asynchronous nbd calls, nbdcopy was blindly treating the completion of an asynchronous command as successful, rather than checking the *error parameter. This could result in the silent creation of a corrupted destination image. | CVSS3: 4.8 | 1% Низкий | больше 4 лет назад | |
CVE-2022-0480 A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can lead to host memory exhaustion due to memcg not limiting the number of Portable Operating System Interface (POSIX) file locks. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2022-0443 Use After Free in GitHub repository vim/vim prior to 8.2. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
CVE-2022-0435 A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network. | CVSS3: 7.1 | 68% Средний | больше 4 лет назад | |
CVE-2022-0433 A NULL pointer dereference flaw was found in the Linux kernel's BPF subsystem in the way a user triggers the map_get_next_key function of the BPF bloom filter. This flaw allows a local user to crash the system. This flaw affects Linux kernel versions prior to 5.17-rc1. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
CVE-2022-0417 Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2. | CVSS3: 7.8 | 2% Низкий | больше 4 лет назад | |
CVE-2022-0413 Use After Free in GitHub repository vim/vim prior to 8.2. | CVSS3: 7.3 | 1% Низкий | больше 4 лет назад | |
CVE-2022-0408 Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | CVSS3: 7.3 | 1% Низкий | больше 4 лет назад | |
CVE-2022-0407 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | CVSS3: 7.3 | 1% Низкий | больше 4 лет назад | |
CVE-2022-0400 An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos. | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
CVE-2022-0396 BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSE_WAIT status for an indefinite period of time, even after the client has terminated the connection. | CVSS3: 5.3 | 3% Низкий | больше 4 лет назад | |
CVE-2022-0393 Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | CVSS3: 7.1 | 1% Низкий | больше 4 лет назад | |
CVE-2022-0392 Heap-based Buffer Overflow in GitHub repository vim prior to 8.2. | CVSS3: 7.8 | 2% Низкий | больше 4 лет назад | |
CVE-2022-0391 A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14. | CVSS3: 5.3 | 8% Низкий | больше 5 лет назад | |
CVE-2022-0382 An information leak flaw was found due to uninitialized memory in the Linux kernel's TIPC protocol subsystem, in the way a user sends a TIPC datagram to one or more destinations. This flaw allows a local user to read some kernel memory. This issue is limited to no more than 7 bytes, and the user cannot control what is read. This flaw affects the Linux kernel versions prior to 5.17-rc1. | CVSS3: 6.2 | 0% Низкий | больше 4 лет назад | |
CVE-2022-0368 Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | CVSS3: 7.8 | 2% Низкий | больше 4 лет назад | |
CVE-2022-0361 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | CVSS3: 7.8 | 2% Низкий | больше 4 лет назад | |
CVE-2022-0359 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу