3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-48065
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c.

CVE-2022-31208
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The webserver contains an endpoint that can execute arbitrary commands by manipulating the cmd_string URL parameter.

CVE-2022-41760
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

An issue was discovered in NOKIA NFM-T R19.9. Relative Path Traversal can occur under /oms1350/data/cpb/log of the Network Element Manager via the filename parameter, allowing a remote authenticated attacker to read arbitrary files.

CVE-2022-28381
Software Genérico General
N/A
UNKNOWN
EPSS
79.3%
2022 2 PoCs

Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a long string to TCP port 888, a related issue to CVE-2017-17932.

CVE-2022-31210
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The binary file /usr/local/sbin/webproject/set_param.cgi contains hardcoded credentials to the web application. Because these accounts cannot be deactivated or have their passwords changed, they are considered to be backdoor accounts.

CVE-2022-32242
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-20 1 PoC

When a user opens manipulated Radiance Picture (.hdr, hdr.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-27458
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Sin descripción disponible.

CVE-2022-32560
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.

CVE-2022-22537
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-20 1 PoC

When a user opens a manipulated Tagged Image File Format (.tiff, 2d.x3d)) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below.

CVE-2022-23884
Software Genérico General
N/A
UNKNOWN
EPSS
5.1%
2022 2 PoCs

Mojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by PurchaseReceiptPacket::_read (packet deserializer).

CVE-2022-29333
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file.

CVE-2022-35020
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 2 PoCs

Advancecomp v2.3 was discovered to contain a heap buffer overflow via the component __interceptor_memcpy at /sanitizer_common/sanitizer_common_interceptors.inc.

CVE-2022-26107
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-20 1 PoC

When a user opens a manipulated Jupiter Tesselation (.jt, JTReader.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-37125
Software Genérico General
N/A
UNKNOWN
EPSS
21.9%
2022 1 PoC

D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.

CVE-2022-0492
kernel General
N/A
UNKNOWN
EPSS
5.2%
2022 CWE-287 12 PoCs

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.

CVE-2022-25342
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Broken Access Control. It does not properly validate requests for access to data and functionality under the /mngset/authset path. By not verifying permissions for access to resources, it allows a potential attacker to view pages that are not allowed.

CVE-2022-29538
Software Genérico General
N/A
UNKNOWN
EPSS
1.7%
2022 1 PoC

RESI Gemini-Net Web 4.2 is affected by Improper Access Control in authorization logic. An unauthenticated user is able to access some critical resources.

CVE-2022-46891
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

An issue was discovered in the Arm Mali GPU Kernel Driver. There is a use-after-free. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Midgard r13p0 through r32p0, Bifrost r1p0 through r40p0, and Valhall r19p0 through r40p0.

CVE-2022-46784
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5.1 GA.)

CVE-2022-50934
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Sin descripción disponible.