3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-0997
Fidelis Network General
3.9
LOW
EPSS
0.5%
2022 CWE-276 2 PoCs

Improper file permissions in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected script files, which could result in arbitrary commands being run as root upon subsequent logon by a root user. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.

CVE-2022-39910
Samsung Pass General
3.9
LOW
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data of Samsung Pass on a certain state of an unlocked device using pop-up view.

CVE-2022-23427
Samsung Mobile Devices General
3.9
LOW
EPSS
0.0%
2022 CWE-20 1 PoC

PendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission via implicit Intent.

CVE-2022-24000
Samsung Mobile Devices General
3.9
LOW
EPSS
0.0%
2022 CWE-20 1 PoC

PendingIntent hijacking vulnerability in DataUsageReminderReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.

CVE-2022-23999
Samsung Mobile Devices General
3.9
LOW
EPSS
0.0%
2022 CWE-20 1 PoC

PendingIntent hijacking vulnerability in CpaReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.

CVE-2022-22287
Samsung Email General
3.9
LOW
EPSS
0.1%
2022 CWE-20 1 PoC

Abitrary file access vulnerability in Samsung Email prior to 6.1.60.16 allows attacker to read isolated data in sandbox.

CVE-2022-36851
Samsung pass General
3.9
LOW
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data of Samsung pass on a certain state of an unlocked device.

CVE-2022-1230
Galaxy S21 General
3.9
LOW
EPSS
0.1%
2022 CWE-601 1 PoC

This vulnerability allows local attackers to execute arbitrary code on affected installations of Samsung Galaxy S21 prior to 4.5.40.5 phones. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of redirections. An attacker can force a redirection to a site that serves malicious content. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the current user. Was ZDI-CAN-15918.

CVE-2022-24001
Samsung Mobile Devices General
3.8
LOW
EPSS
0.0%
2022 CWE-200 1 PoC

Information disclosure vulnerability in Edge Panel prior to Android S(12) allows physical attackers to access screenshot in clipboard via Edge Panel.

CVE-2022-0841
ljharb/npm-lockfile General
3.8
LOW
EPSS
0.5%
2022 CWE-78 1 PoC

OS Command Injection in GitHub repository ljharb/npm-lockfile in v2.0.3 and v2.0.4.

CVE-2022-43772
Pentaho Business Analytics Server General
3.8
LOW
EPSS
0.3%
2022 CWE-532 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin expose the username and password of clusters in clear text into system logs. 

CVE-2022-1385
Mattermost General
3.7
LOW
EPSS
0.2%
2022 CWE-664 1 PoC

Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users to join the workspace and access information from the public teams and channels.

CVE-2022-1548
Mattermost Playbooks General
3.7
LOW
EPSS
0.2%
2022 CWE-264 1 PoC

Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook members to escalate their membership privileges and perform actions restricted to playbook admins.

CVE-2022-2872
octoprint/octoprint General
3.7
LOW
EPSS
0.2%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3.

CVE-2022-3457
ikus060/rdiffweb General
3.7
LOW
EPSS
0.2%
2022 CWE-346 1 PoC

Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5.

CVE-2022-0085
dompdf/dompdf General
3.7
LOW
EPSS
0.4%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository dompdf/dompdf prior to 2.0.0.

CVE-2022-34394
Dell Networking OS10 General
3.7
LOW
EPSS
0.1%
2022 CWE-295 1 PoC

Dell OS10, version 10.5.3.4, contains an Improper Certificate Validation vulnerability in Support Assist. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized access to limited switch configuration data. The vulnerability could be leveraged by attackers to conduct man-in-the-middle attacks to gain access to the Support Assist information.

CVE-2022-21164
node-lmdb General
3.7
LOW
EPSS
0.3%
2022 1 PoC

The package node-lmdb before 0.9.7 are vulnerable to Denial of Service (DoS) when defining a non-invokable ToString value, which will cause a crash during type check.

CVE-2022-26308
Pandora FMS General
3.7
LOW
EPSS
0.2%
2022 CWE-284 1 PoC

Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write) could create, delete, view existing keys which are outside the intended role.

CVE-2022-42965
snowflake-connector-python General
3.7
LOW
EPSS
0.2%
2022 CWE-1333 1 PoC

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI package, when an attacker is able to supply arbitrary input to the undocumented get_file_transfer_type method