3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-22833
Software Genérico General
N/A
UNKNOWN
EPSS
24.7%
2022 3 PoCs

An issue was discovered in Servisnet Tessa 0.0.2. An attacker can obtain sensitive information via a /js/app.js request.

CVE-2022-48675
Linux General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In the Linux kernel, the following vulnerability has been resolved: IB/core: Fix a nested dead lock as part of ODP flow Fix a nested dead lock as part of ODP flow by using mmput_async(). From the below call trace [1] can see that calling mmput() once we have the umem_odp->umem_mutex locked as required by ib_umem_odp_map_dma_and_lock() might trigger in the same task the exit_mmap()->__mmu_notifier_release()->mlx5_ib_invalidate_range() which may dead lock when trying to lock the same mutex. Moving to use mmput_async() will solve the problem as the above exit_mmap() flow will be called in oth

CVE-2022-0850
kernel General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-200 1 PoC

A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace.

CVE-2022-1016
Kernel General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-824 1 PoC

A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle 'return' with proper preconditions, as it can lead to a kernel information leak problem caused by a local, unprivileged attacker.

CVE-2022-39838
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allows absolute path traversal to local pathnames.

CVE-2022-31266
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to take over accounts.

CVE-2022-25264
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases.

CVE-2022-48333
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_verify_keys prefix_len+feature_name_len integer overflow and resultant buffer overflow.

CVE-2022-40090
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

An issue was discovered in function TIFFReadDirectory libtiff before 4.4.0 allows attackers to cause a denial of service via crafted TIFF file.

CVE-2022-30319
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Saia Burgess Controls (SBC) PCD through 2022-05-06 allows Authentication bypass. According to FSCT-2022-0062, there is a Saia Burgess Controls (SBC) PCD S-Bus authentication bypass issue. The affected components are characterized as: S-Bus (5050/UDP) authentication. The potential impact is: Authentication bypass. The Saia Burgess Controls (SBC) PCD controllers utilize the S-Bus protocol (5050/UDP) for a variety of engineering purposes. It is possible to configure a password in order to restrict access to sensitive engineering functionality. Authentication functions on the basis of a MAC/IP whi

CVE-2022-29156
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_release.

CVE-2022-0778
OpenSSL General
N/A
UNKNOWN
EPSS
7.5%
2022 15 PoCs

The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate ma

CVE-2022-32245
SAP BusinessObjects Business Intelligence Platform (Open Document) General
N/A
UNKNOWN
EPSS
0.6%
2022 CWE-319 1 PoC

SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attacker to retrieve sensitive information plain text over the network. On successful exploitation, the attacker can view any data available for a business user and put load on the application by an automated attack. Thus, completely compromising confidentiality but causing a limited impact on the availability of the application.

CVE-2022-30551
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2022 1 PoC

OPC UA Legacy Java Stack 2022-04-01 allows a remote attacker to cause a server to stop processing messages by sending crafted messages that exhaust available resources.

CVE-2022-29900
AMD Processors General
N/A
UNKNOWN
EPSS
1.4%
2022 1 PoC

Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.

CVE-2022-27667
SAP BusinessObjects Business Intelligence Platform General
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-200 2 PoCs

Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management Console (CMC) - version 430, allows an attacker to access information which would otherwise be restricted, leading to Information Disclosure.

CVE-2022-35131
Software Genérico General
N/A
UNKNOWN
EPSS
15.3%
2022 1 PoC

Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.

CVE-2022-27135
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to cause a Denial of Service (Segmentation fault) or other unspecified effects by sending a crafted PDF file to the pdftoppm binary.

CVE-2022-29777
Software Genérico General
N/A
UNKNOWN
EPSS
16.2%
2022 1 PoC

Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via the component DesktopEditor/fontengine/fontconverter/FontFileBase.h.

CVE-2022-25375
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive information from kernel memory.