3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-28349
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 2 PoCs

Arm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 before r24p0, and Valhall r19p0 through r23p0 before r24p0.

CVE-2022-38844
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating contacts with payloads capable of executing system commands. Admin user exporting contacts in CSV file may end up executing the malicious system commands on his system.

CVE-2022-23824
AMD Processors General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.

CVE-2022-27094
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Sony PlayMemories Home v6.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

CVE-2022-34970
Software Genérico General
N/A
UNKNOWN
EPSS
24.0%
2022 2 PoCs

Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitation this vulnerability allows attackers to remotely execute arbitrary code in the context of the vulnerable service.

CVE-2022-3239
Kernel General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-416 1 PoC

A flaw use after free in the Linux kernel video4linux driver was found in the way user triggers em28xx_usb_probe() for the Empia 28xx based TV cards. A local user could use this flaw to crash the system or potentially escalate their privileges on the system.

CVE-2022-29298
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
81.1%
2022 1 PoC

SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.

CVE-2022-28478
Software Genérico General
N/A
UNKNOWN
EPSS
1.3%
2022 1 PoC

SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sanitize user input allowing attackers with admin privileges to delete arbitrary files on the remote system.

CVE-2022-46484
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to view the password to access and arbitrarily submit surveys.

CVE-2022-1354
libtiff General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-125 1 PoC

A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service.

CVE-2022-32115
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG file.

CVE-2022-27657
SAP Focused Run (Simple Diagnostics Agent) General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-22 2 PoCs

A highly privileged remote attacker, can gain unauthorized access to display contents of restricted directories by exploiting insufficient validation of path information in SAP Focused Run (Simple Diagnostics Agent 1.0) - version 1.0.

CVE-2022-38183
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the issue). As a result, the attacker would get access to private issue titles.

CVE-2022-31464
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Insecure permissions configuration in Adaware Protect v1.2.439.4251 allows attackers to escalate privileges via changing the service binary path.

CVE-2022-28215
SAP NetWeaver ABAP Server and ABAP Platform General
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-601 1 PoC

SAP NetWeaver ABAP Server and ABAP Platform - versions 740, 750, 787, allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked to disclose personal information.

CVE-2022-27337
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

CVE-2022-33707
FindMyMobile General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-334 1 PoC

Improper identifier creation logic in Find My Mobile prior to version 7.2.24.12 allows attacker to identify the device.

CVE-2022-36617
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Arq Backup 7.19.5.0 and below stores backup encryption passwords using reversible encryption. This issue allows attackers with administrative privileges to recover cleartext passwords.

CVE-2022-0617
Kernel General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-476 2 PoCs

A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc1 till 5.17-rc2.

CVE-2022-39803
SAP 3D Visual Enterprise Author General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated ACIS Part and Assembly (.sat, CoreCadTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.