3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-4891
Sisimai General
3.5
LOW
EPSS
0.3%
2022 CWE-1333 1 PoC

A vulnerability has been found in Sisimai up to 4.25.14p11 and classified as problematic. This vulnerability affects the function to_plain of the file lib/sisimai/string.rb. The manipulation leads to inefficient regular expression complexity. The exploit has been disclosed to the public and may be used. Upgrading to version 4.25.14p12 is able to address this issue. The name of the patch is 51fe2e6521c9c02b421b383943dc9e4bbbe65d4e. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-218452.

CVE-2022-2690
Wedding Hall Booking System General
3.5
LOW
EPSS
0.2%
2022 CWE-79 1 PoC

A vulnerability classified as problematic was found in SourceCodester Wedding Hall Booking System. Affected by this vulnerability is an unknown functionality of the file /whbs/?page=my_bookings of the component Booking Form. The manipulation of the argument Remarks leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205813 was assigned to this vulnerability.

CVE-2022-0697
archivy/archivy General
3.4
LOW
EPSS
0.2%
2022 CWE-601 1 PoC

Open Redirect in GitHub repository archivy/archivy prior to 1.7.0.

CVE-2022-30751
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_DHCPACK_EVENT action.

CVE-2022-27575
Samsung Mobile Devices General
3.3
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Information exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission.

CVE-2022-33724
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-200 1 PoC

Exposure of Sensitive Information in Samsung Dialer application?prior to SMR Aug-2022 Release 1 allows local attackers to access ICCID via log.

CVE-2022-30750
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in updateLastConnectedClientInfo function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected.

CVE-2022-46781
Software Genérico General
3.3
LOW
EPSS
0.2%
2022 1 PoC

An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU memory processing operations to access a limited amount outside of buffer bounds. This affects Valhall r29p0 through r41p0 before r42p0 and Avalon r41p0 before r42p0.

CVE-2022-43640
PDF Reader General
3.3
LOW
EPSS
0.9%
2022 CWE-125 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 12.0.1.12430. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18629.

CVE-2022-25821
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-125 1 PoC

Improper use of SMS buffer pointer in Shannon baseband prior to SMR Mar-2022 Release 1 allows OOB read.

CVE-2022-30741
Find My Mobile General
3.3
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Sensitive information exposure vulnerability in SimChangeAlertManger of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permission to get sim card information through device log.

CVE-2022-23994
Samsung Wearable Devices General
3.3
LOW
EPSS
0.2%
2022 CWE-284 1 PoC

An Improper access control vulnerability in StBedtimeModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.

CVE-2022-28670
PDF Reader General
3.3
LOW
EPSS
0.2%
2022 CWE-125 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of AcroForms. Crafted data in an AcroForm can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16523.

CVE-2022-33698
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-200 1 PoC

Exposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows local attackers to access ICCID via log.

CVE-2022-43641
PDF Reader General
3.3
LOW
EPSS
0.9%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 12.0.1.12430. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18894

CVE-2022-31237
PowerScale OneFS General
3.3
LOW
EPSS
0.0%
2022 CWE-281 1 PoC

Dell PowerScale OneFS, versions 9.2.0 up to and including 9.2.1.12 and 9.3.0.5 contain an improper preservation of permissions vulnerability in SyncIQ. A low privileged local attacker may potentially exploit this vulnerability, leading to limited information disclosure.

CVE-2022-36835
Samsung Internet Browser General
3.3
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Implicit Intent hijacking vulnerability in Samsung Internet Browser prior to version 17.0.7.34 allows attackers to access arbitrary files.

CVE-2022-39893
Galaxy Buds Pro Manager General
3.3
LOW
EPSS
0.1%
2022 CWE-532 1 PoC

Sensitive information exposure vulnerability in FmmBaseModel in Galaxy Buds Pro Manage prior to version 4.1.22092751 allows local attackers with log access permission to get device identifier data through device log.

CVE-2022-47952
Software Genérico General
3.3
LOW
EPSS
2.5%
2022 1 PoC

lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace path" often indicates that a file exists. NOTE: this is different from CVE-2018-6556 because the CVE-2018-6556 fix design was based on the premise that "we will report back to the user that the open() failed but the user has no way of knowing why it failed"; however, in many realistic cases, there are no plausible reasons

CVE-2022-27839
Samsung Internet General
3.3
LOW
EPSS
0.2%
2022 CWE-287 1 PoC

Improper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab without proper credentials.