3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-24370
PDF Reader General
3.3
LOW
EPSS
0.5%
2022 CWE-125 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader Foxit reader 11.0.1.0719 macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of XFA forms. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context o

CVE-2022-20338
Android General
3.3
LOW
EPSS
0.1%
2022 4 PoCs

In HierarchicalUri.readFrom of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to a local escalation of privilege, preventing processes from validating URIs correctly, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-171966843

CVE-2022-36834
Game Launcher General
3.3
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows local attacker to access app data with user interaction.

CVE-2022-30752
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_STATE_CHANGED action.

CVE-2022-3257
Mattermost General
3.1
LOW
EPSS
0.4%
2022 CWE-400 1 PoC

Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.

CVE-2022-30629
crypto/tls General
3.1
LOW
EPSS
0.1%
2022 1 PoC

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

CVE-2022-3147
Mattermost General
3.1
LOW
EPSS
1.2%
2022 CWE-400 1 PoC

Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated users to cause resource exhaustion on specific system configurations, resulting in server-side Denial of Service.

CVE-2022-4665
ampache/ampache General
3.1
LOW
EPSS
0.2%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6.

CVE-2022-27831
Samsung Mobile Devices General
2.9
LOW
EPSS
0.0%
2022 CWE-125 1 PoC

Improper boundary check in sflvd_rdbuf_bits of libsflvextractor prior to SMR Apr-2022 Release 1 allows attackers to read out of bounds memory.

CVE-2022-27834
Samsung Mobile Devices General
2.9
LOW
EPSS
0.0%
2022 CWE-367 1 PoC

Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-2022 Release 1 allows attackers to perform malicious actions.

CVE-2022-2061
hpjansson/chafa General
2.8
LOW
EPSS
0.1%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository hpjansson/chafa prior to 1.12.0.

CVE-2022-36877
Samsung Members General
2.8
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Exposure of Sensitive Information in FaqSymptomCardViewModel in Samsung Members prior to versions 4.3.00.11 in Global and 14.0.02.4 in China allows local attackers to access device identification via log.

CVE-2022-3363
ikus060/rdiffweb General
2.8
LOW
EPSS
0.5%
2022 CWE-840 1 PoC

Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.0a7.

CVE-2022-22283
Samsung Health General
2.8
LOW
EPSS
0.1%
2022 CWE-287 1 PoC

Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health App.

CVE-2022-4070
librenms/librenms General
2.7
LOW
EPSS
0.0%
2022 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.

CVE-2022-30607
Robotic Process Automation General
2.7
LOW
EPSS
0.4%
2022 1 PoC

IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow a user to obtain sensitive information due to information properly masked in the control center UI. IBM X-Force ID: 227294.

CVE-2022-2841
Falcon General
2.7
LOW
EPSS
10.4%
2022 CWE-862 3 PoCs

A vulnerability was found in CrowdStrike Falcon 6.31.14505.0/6.42.15610/6.44.15806. It has been classified as problematic. Affected is an unknown function of the component Uninstallation Handler. The manipulation leads to missing authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 6.40.15409, 6.42.15611 and 6.44.15807 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-206880.

CVE-2022-4882
mwEmbed General
2.6
LOW
EPSS
0.2%
2022 CWE-79 1 PoC

A vulnerability was found in kaltura mwEmbed up to 2.91. It has been rated as problematic. Affected by this issue is some unknown functionality of the file modules/KalturaSupport/components/share/share.js of the component Share Plugin. The manipulation of the argument res leads to cross site scripting. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.92.rc1 is able to address this issue. The name of the patch is 4f11b6f6610acd6d89de5f8b

CVE-2022-1987
bfabiszewski/libmobi General
2.5
LOW
EPSS
0.2%
2022 CWE-126 1 PoC

Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.

CVE-2022-30720
Samsung Mobile Devices General
2.5
LOW
EPSS
0.1%
2022 CWE-20 1 PoC

Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.