3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-41973
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling, which could lead to controlled file writes outside of the /dev/shm directory. This could be used indirectly for local privilege escalation to root.

CVE-2022-44721
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Sin descripción disponible.

CVE-2022-38334
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

XPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog::countPageTree() at Catalog.cc.

CVE-2022-32243
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-20 1 PoC

When a user opens manipulated Scalable Vector Graphics (.svg, svg.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-37393
Zimbra Server General
N/A
UNKNOWN
EPSS
5.1%
2022 CWE-284 1 PoC

Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.

CVE-2022-24675
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.

CVE-2022-29616
SAP NetWeaver and ABAP Platform General
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-787 1 PoC

SAP Host Agent, SAP NetWeaver and ABAP Platform allow an attacker to leverage logical errors in memory management to cause a memory corruption.

CVE-2022-50807
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Sin descripción disponible.

CVE-2022-26878
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 3 PoCs

drivers/bluetooth/virtio_bt.c in the Linux kernel before 5.16.3 has a memory leak (socket buffers have memory allocated but not freed).

CVE-2022-32317
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

The MPlayer Project v1.5 was discovered to contain a heap use-after-free resulting in a double free in the preinit function at libvo/vo_v4l2.c. This vulnerability can lead to a Denial of Service (DoS) via a crafted file. The device=strdup statement is not executed on every call. Note: This has been disputed by third parties as invalid and not reproduceable.

CVE-2022-31659
VMware Workspace ONE Access, Identity Manager and vRealize Automation General
N/A
UNKNOWN
EPSS
1.7%
2022 1 PoC

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.

CVE-2022-29864
Software Genérico General
N/A
UNKNOWN
EPSS
1.4%
2022 1 PoC

OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontrolled Resource Consumption.

CVE-2022-32248
SAP S/4HANA General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-20 1 PoC

Due to missing input validation in the Manage Checkbooks component of SAP S/4HANA - version 101, 102, 103, 104, 105, 106, an attacker could insert or edit the value of an existing field in the database. This leads to an impact on the integrity of the data.

CVE-2022-35911
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

On Patlite NH-FB series devices through 1.46, remote attackers can cause a denial of service by omitting the query string. NOTE: the vendor's perspective is that "omitting the query string does not cause a denial of service and the indicated event can not be reproduced.

CVE-2022-23332
Software Genérico General
N/A
UNKNOWN
EPSS
12.8%
2022 1 PoC

Command injection vulnerability in Manual Ping Form (Web UI) in Shenzhen Ejoin Information Technology Co., Ltd. ACOM508/ACOM516/ACOM532 609-915-041-100-020 allows a remote attacker to inject arbitrary code via the field.

CVE-2022-27666
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 3 PoCs

A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.

CVE-2022-32387
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2022 1 PoC

In Kentico before 13.0.66, attackers can achieve Denial of Service via a crafted request to the GetResource handler.

CVE-2022-24449
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2022 1 PoC

Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document.

CVE-2022-39960
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
34.8%
2022 0 PoCs

The Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all groups from the Jira instance by making a groupexport_download=true request to a plugins/servlet/groupexportforjira/admin/ URI.

CVE-2022-1043
Kernel General
N/A
UNKNOWN
EPSS
21.6%
2022 CWE-416 1 PoC

A flaw was found in the Linux kernel’s io_uring implementation. This flaw allows an attacker with a local account to corrupt system memory, crash the system or escalate privileges.