9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-28680
PDF Reader General
7.8
HIGH
EPSS
0.4%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16821.

CVE-2022-40304
Software Genérico General
7.8
HIGH
EPSS
0.2%
2022 5 PoCs

An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.

CVE-2022-32898
macOS General
7.8
HIGH
EPSS
5.3%
2022 1 PoC

The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7 and iPadOS 15.7, iOS 16, macOS Ventura 13, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.

CVE-2022-25478
Software Genérico General
7.8
HIGH
EPSS
0.2%
2022 1 PoC

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 provides read and write access to the PCI configuration space of the device.

CVE-2022-2208
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.5163.

CVE-2022-2231
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.

CVE-2022-38691
SC9863A//T310/T610/T618/ General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

In BootROM, there is a possible missing validation for Certificate Type 0. This could lead to local escalation of privilege with no additional execution privileges needed.

CVE-2022-2257
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

CVE-2022-41034
Visual Studio Code General
7.8
HIGH
EPSS
63.2%
2022 1 PoC

Visual Studio Code Remote Code Execution Vulnerability

CVE-2022-43664
Ichitaro General
7.8
HIGH
EPSS
0.4%
2022 CWE-416 2 PoCs

A use-after-free vulnerability exists within the way Ichitaro Word Processor 2022, version 1.0.1.57600, processes protected documents. A specially crafted document can trigger reuse of freed memory, which can lead to further memory corruption and potentially result in arbitrary code execution. An attacker can provide a malicious document to trigger this vulnerability.

CVE-2022-4095
Kernel General
7.8
HIGH
EPSS
0.0%
2022 CWE-416 1 PoC

A use-after-free flaw was found in Linux kernel before 5.19.2. This issue occurs in cmd_hdl_filter in drivers/staging/rtl8712/rtl8712_cmd.c, allowing an attacker to launch a local denial of service attack and gain escalation of privileges.

CVE-2022-42046
Software Genérico General
7.8
HIGH
EPSS
0.2%
2022 2 PoCs

wfshbr64.sys and wfshbr32.sys specially crafted IOCTL allows arbitrary user to perform local privilege escalation

CVE-2022-1116
Kernel General
7.8
HIGH
EPSS
0.2%
2022 CWE-190 1 PoC

Integer Overflow or Wraparound vulnerability in io_uring of Linux Kernel allows local attacker to cause memory corruption and escalate privileges to root. This issue affects: Linux Kernel versions prior to 5.4.189; version 5.4.24 and later versions.

CVE-2022-30174
Microsoft 365 Apps for Enterprise General
7.8
HIGH
EPSS
2.9%
2022 1 PoC

Microsoft Office Remote Code Execution Vulnerability

CVE-2022-28672
PDF Reader General
7.8
HIGH
EPSS
22.0%
2022 CWE-416 3 PoCs

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16640.

CVE-2022-4510
binwalk General
7.8
HIGH
EPSS
44.1%
2022 CWE-22 4 PoCs

A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By crafting a malicious PFS filesystem file, an attacker can get binwalk's PFS extractor to extract files at arbitrary locations when binwalk is run in extraction mode (-e option). Remote code execution can be achieved by building a PFS filesystem that, upon extraction, would extract a malicious binwalk module into the folder .config/binwalk/plugins. This vulnerability is associated with program files src/binwalk/plugins/unpfs.py. This issue affects binwalk from 2.1.2b through 2.3

CVE-2022-41322
Software Genérico General
7.8
HIGH
EPSS
1.4%
2022 1 PoC

In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.

CVE-2022-45988
Software Genérico General
7.8
HIGH
EPSS
1.3%
2022 1 PoC

starsoftcomm CooCare 5.304 allows local attackers to escalate privileges and execute arbitrary commands via a crafted file upload.

CVE-2022-28678
PDF Reader General
7.8
HIGH
EPSS
0.4%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16805.

CVE-2022-3235
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0490.