9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-43310
Software Genérico General
7.8
HIGH
EPSS
0.0%
2022 1 PoC

An Uncontrolled Search Path Element in Foxit Software released Foxit Reader v11.2.118.51569 allows attackers to escalate privileges when searching for DLL libraries without specifying an absolute path.

CVE-2022-28669
PDF Reader General
7.8
HIGH
EPSS
0.4%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16420.

CVE-2022-32168
notepad-plus-plus General
7.8
HIGH
EPSS
0.1%
2022 CWE-427 1 PoC

Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

CVE-2022-4956
Advanced Installer General
7.8
HIGH
EPSS
0.2%
2022 CWE-427 1 PoC

A vulnerability classified as critical has been found in Caphyon Advanced Installer 19.7. This affects an unknown part of the component WinSxS DLL Handler. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. Upgrading to version 19.7.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-240903.

CVE-2022-28679
PDF Reader General
7.8
HIGH
EPSS
0.4%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16861.

CVE-2022-42274
NVIDIA DGX servers General
7.8
HIGH
EPSS
0.2%
2022 CWE-120 1 PoC

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution.

CVE-2022-46701
tvOS General
7.8
HIGH
EPSS
0.2%
2022 3 PoCs

The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2. Connecting to a malicious NFS server may lead to arbitrary code execution with kernel privileges.

CVE-2022-22960
🔥 KEV VMware Workspace ONE Access, Identity Manager and vRealize Automation General
7.8
HIGH
EPSS
72.7%
2022 3 PoCs

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.

CVE-2022-43701
Arm Compiler 5 (AC5), Arm Compiler for Embedded 6 (AC6), Fast Models (FM), Arm Compiler for Embedded FuSA (ACEF), Arm Development Studio (ADS), Arm Forge (AF), Arm Mobile Studio (AMS), DS-5 Development Studio, Fast Models (FM), GNU Toolchain (GT), Keil MDK (KMDK), Mbed Studio (MS) General
7.8
HIGH
EPSS
0.1%
2022 CWE-276 1 PoC

When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code.

CVE-2022-27677
Ryzen™ Master General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to modify files potentially leading to privilege escalation and code execution by the lower privileged user.

CVE-2022-2129
vim/vim General
7.8
HIGH
EPSS
0.2%
2022 CWE-787 1 PoC

Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.

CVE-2022-25973
mc-kill-port General
7.8
HIGH
EPSS
0.3%
2022 1 PoC

All versions of package mc-kill-port are vulnerable to Arbitrary Command Execution via the kill function, due to missing sanitization of the port argument.

CVE-2022-23804
KiCad General
7.8
HIGH
EPSS
0.7%
2022 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadIJCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-2286
vim/vim General
7.8
HIGH
EPSS
0.2%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

CVE-2022-0729
vim/vim General
7.8
HIGH
EPSS
0.5%
2022 CWE-823 2 PoCs

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.

CVE-2022-44830
Software Genérico General
7.8
HIGH
EPSS
6.5%
2022 1 PoC

Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.

CVE-2022-42850
iOS and iPadOS General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary code with kernel privileges.

CVE-2022-0847
🔥 KEV kernel General
7.8
HIGH
EPSS
82.3%
2022 CWE-665 102 PoCs

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.

CVE-2022-1154
vim/vim General
7.8
HIGH
EPSS
1.6%
2022 CWE-416 2 PoCs

Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.

CVE-2022-45115
Ichitaro General
7.8
HIGH
EPSS
0.4%
2022 CWE-122 2 PoCs

A buffer overflow vulnerability exists in the Attribute Arena functionality of Ichitaro 2022 1.0.1.57600. A specially crafted document can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.