9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-32907
iOS General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

This issue was addressed with improved checks. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.

CVE-2022-49328
Linux General
7.8
HIGH
EPSS
0.0%
2022 1 PoC

In the Linux kernel, the following vulnerability has been resolved: mt76: fix use-after-free by removing a non-RCU wcid pointer Fixes an issue caught by KASAN about use-after-free in mt76_txq_schedule by protecting mtxq->wcid with rcu_lock between mt76_txq_schedule and sta_info_[alloc, free]. [18853.876689] ================================================================== [18853.876751] BUG: KASAN: use-after-free in mt76_txq_schedule+0x204/0xaf8 [mt76] [18853.876773] Read of size 8 at addr ffffffaf989a2138 by task mt76-tx phy0/883 [18853.876786] [18853.876810] CPU: 5 PID: 883 Comm: mt76-tx

CVE-2022-2304
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-121 1 PoC

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.

CVE-2022-32894
🔥 KEV iOS and iPadOS General
7.8
HIGH
EPSS
0.2%
2022 2 PoCs

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.

CVE-2022-20470
Android General
7.8
HIGH
EPSS
0.0%
2022 1 PoC

In bindRemoteViewsService of AppWidgetServiceImpl.java, there is a possible way to bypass background activity launch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-234013191

CVE-2022-45415
Firefox General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox < 107.

CVE-2022-3977
Kernel General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

A use-after-free flaw was found in the Linux kernel MCTP (Management Component Transport Protocol) functionality. This issue occurs when a user simultaneously calls DROPTAG ioctl and socket close happens, which could allow a local user to crash the system or potentially escalate their privileges on the system.

CVE-2022-20489
Android General
7.8
HIGH
EPSS
0.0%
2022 2 PoCs

In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242703460

CVE-2022-2183
vim/vim General
7.8
HIGH
EPSS
0.6%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

CVE-2022-41302
FBX SDK General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

An Out-Of-Bounds Read Vulnerability in Autodesk FBX SDK version 2020. and prior may lead to code execution or information disclosure through maliciously crafted FBX files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

CVE-2022-42899
Software Genérico General
7.8
HIGH
EPSS
0.7%
2022 1 PoC

Bentley MicroStation and MicroStation-based applications may be affected by out-of-bounds read and stack overflow issues when opening crafted SKP files. Exploiting these issues could lead to information disclosure and code execution. The fixed versions are 10.17.01.58* for MicroStation and 10.17.01.19* for Bentley View.

CVE-2022-41201
SAP 3D Visual Enterprise Viewer General
7.8
HIGH
EPSS
1.1%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated Right Hemisphere Binary (.rh, rh.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVE-2022-4744
Kernel General
7.8
HIGH
EPSS
0.1%
2022 CWE-460 1 PoC

A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGISTER notifier). This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVE-2022-20456
Android General
7.8
HIGH
EPSS
0.0%
2022 1 PoC

In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242703780

CVE-2022-2453
gpac/gpac General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository gpac/gpac prior to 2.1-DEV.

CVE-2022-3256
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0530.

CVE-2022-37706
Software Genérico General
7.8
HIGH
EPSS
56.2%
2022 9 PoCs

enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and the system library function mishandles pathnames that begin with a /dev/.. substring.

CVE-2022-1851
vim/vim General
7.8
HIGH
EPSS
0.2%
2022 CWE-125 2 PoCs

Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

CVE-2022-2288
vim/vim General
7.8
HIGH
EPSS
0.5%
2022 CWE-787 1 PoC

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.