3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-36354
OpenImageIO General
5.3
MEDIUM
EPSS
0.1%
2022 CWE-193 1 PoC

A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.19.0. More specifically, in the way run-length encoded byte spans are handled. A malformed RLA file can lead to an out-of-bounds read of heap metadata which can result in sensitive information leak. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-0613
medialize/uri.js General
5.3
MEDIUM
EPSS
0.1%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.

CVE-2022-23813
2nd Gen EPYC General
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

The software interfaces to ASP and SMU may not enforce the SNP memory security policy resulting in a potential loss of integrity of guest memory in a confidential compute environment.

CVE-2022-37312
Software Genérico General
5.3
MEDIUM
EPSS
0.9%
2022 1 PoC

OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to the deferrer servlet.

CVE-2022-2930
octoprint/octoprint General
5.3
MEDIUM
EPSS
0.1%
2022 CWE-620 1 PoC

Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.

CVE-2022-21222
css-what General
5.3
MEDIUM
EPSS
0.3%
2022 1 PoC

The package css-what before 2.1.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of insecure regular expression in the re_attr variable of index.js. The exploitation of this vulnerability could be triggered via the parse function.

CVE-2022-46371
AR7088H-A General
5.3
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

Alotcer - AR7088H-A firmware version 16.10.3 Information disclosure. Unspecified error message contains the default administrator user name.

CVE-2022-42265
NVIDIA GPU Display Driver for Linux General
5.3
MEDIUM
EPSS
0.1%
2022 CWE-190 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to information disclosure or data tampering.

CVE-2022-48753
Linux General
5.3
MEDIUM
EPSS
0.0%
2022 1 PoC

In the Linux kernel, the following vulnerability has been resolved: block: fix memory leak in disk_register_independent_access_ranges kobject_init_and_add() takes reference even when it fails. According to the doc of kobject_init_and_add() If this function returns an error, kobject_put() must be called to properly clean up the memory associated with the object. Fix this issue by adding kobject_put(). Callback function blk_ia_ranges_sysfs_release() in kobject_put() can handle the pointer "iars" properly.

CVE-2022-3222
gpac/gpac General
5.3
MEDIUM
EPSS
0.1%
2022 CWE-674 2 PoCs

Uncontrolled Recursion in GitHub repository gpac/gpac prior to 2.1.0-DEV.

CVE-2022-0689
microweber/microweber General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-840 1 PoC

Use multiple time the one-time coupon in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-23429
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.0%
2022 CWE-125 1 PoC

An improper boundary check in audio hal service prior to SMR Feb-2022 Release 1 allows attackers to read invalid memory and it leads to application crash.

CVE-2022-26949
Software Genérico General
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Archer 6.x through 6.9 SP2 P1 (6.9.2.1) contains an improper access control vulnerability on attachments. A remote authenticated malicious user could potentially exploit this vulnerability to gain access to files that should only be allowed by extra privileges.

CVE-2022-45213
Software Genérico General
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

perfSONAR before 4.4.6 inadvertently supports the parse option for a file:// URL.

CVE-2022-25927
ua-parser-js General
5.3
MEDIUM
EPSS
1.5%
2022 CWE-1333 2 PoCs

Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.

CVE-2022-36318
Firefox ESR General
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.

CVE-2022-1437
radareorg/radare2 General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

CVE-2022-0133
chocobozzz/peertube General
5.3
MEDIUM
EPSS
0.3%
2022 CWE-284 1 PoC

peertube is vulnerable to Improper Access Control

CVE-2022-41977
OpenImageIO General
5.3
MEDIUM
EPSS
0.1%
2022 CWE-125 1 PoC

An out of bounds read vulnerability exists in the way OpenImageIO version v2.3.19.0 processes string fields in TIFF image files. A specially-crafted TIFF file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.