3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-23434
Bixby Vision General
4.4
MEDIUM
EPSS
0.1%
2022 CWE-94 1 PoC

A vulnerability using PendingIntent in Bixby Vision prior to versions 3.7.60.8 in Android S(12), 3.7.50.6 in Andorid R(11) and below allows attackers to execute privileged action by hijacking and modifying the intent.

CVE-2022-28793
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2022 CWE-754 1 PoC

Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent change of Android ROT after first initialization at boot time.

CVE-2022-36843
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2022 CWE-122 1 PoC

A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

CVE-2022-27573
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

Improper input validation vulnerability in parser_infe and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by privileged attackers.

CVE-2022-28777
Samsung Members General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in Samsung Members prior to version 13.6.08.5 allows local attacker to execute call function without CALL_PHONE permission.

CVE-2022-39884
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information.

CVE-2022-4280
Smart Campus System General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-266 1 PoC

A vulnerability, which was classified as problematic, has been found in Dot Tech Smart Campus System. Affected by this issue is some unknown functionality of the file /services/Card/findUser. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-214778 is the identifier assigned to this vulnerability.

CVE-2022-22108
DaybydayCRM General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest privileges account (employee type user), can view the absences of all users in the system including administrators. This type of user is not authorized to view this kind of information.

CVE-2022-25779
GateManager General
4.3
MEDIUM
EPSS
0.3%
2022 CWE-779 1 PoC

Logging of Excessive Data vulnerability in audit log of Secomea GateManager allows logged in user to write text entries in audit log. This issue affects: Secomea GateManager versions prior to 9.7.

CVE-2022-3807
Bento4 General
4.3
MEDIUM
EPSS
0.3%
2022 CWE-404 1 PoC

A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Incomplete Fix CVE-2019-13238. The manipulation leads to resource consumption. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212660.

CVE-2022-42300
Software Genérico General
4.3
MEDIUM
EPSS
0.5%
2022 1 PoC

An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server nbars process can be crashed resulting in a denial of service. (Note: the watchdog service will automatically restart the process.)

CVE-2022-3301
ikus060/rdiffweb General
4.3
MEDIUM
EPSS
0.3%
2022 CWE-460 1 PoC

Improper Cleanup on Thrown Exception in GitHub repository ikus060/rdiffweb prior to 2.4.8.

CVE-2022-2408
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2022 CWE-200 1 PoC

The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.

CVE-2022-32169
bytebase General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-285 1 PoC

The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user can view the “OPEN” and “CLOSED” issues by “Admin” and the affected endpoint is “/issue”.

CVE-2022-3292
ikus060/rdiffweb General
4.3
MEDIUM
EPSS
0.3%
2022 CWE-524 1 PoC

Use of Cache Containing Sensitive Information in GitHub repository ikus060/rdiffweb prior to 2.4.8.

CVE-2022-39887
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to configure EDM setting.

CVE-2022-0904
Mattermost General
4.3
MEDIUM
EPSS
0.4%
2022 1 PoC

A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted Apple Pages document.

CVE-2022-2252
microweber/microweber General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-601 1 PoC

Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.

CVE-2022-1350
GhostPCL General
4.3
MEDIUM
EPSS
0.4%
2022 CWE-119 1 PoC

A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The manipulation with a malicious file leads to a memory corruption. The attack can be initiated remotely but requires user interaction. The exploit has been disclosed to the public as a POC and may be used. It is recommended to apply the patches to fix this issue.

CVE-2022-1079
One Church Management System General
4.3
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

A vulnerability classified as problematic has been found in SourceCodester One Church Management System. Affected are multiple files and parameters which are prone to to cross site scripting. It is possible to launch the attack remotely.