3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-26240
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The default privileges for the running service Normand Message Buffer in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data.

CVE-2022-33082
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2022 1 PoC

An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2022-35295
SAP Host Agent (SAPOSCOL) General
N/A
UNKNOWN
EPSS
1.2%
2022 CWE-755 3 PoCs

In SAP Host Agent (SAPOSCOL) - version 7.22, an attacker may use files created by saposcol to escalate privileges for themselves.

CVE-2022-32238
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-20 1 PoC

When a user opens manipulated Encapsulated Post Script (.eps, ai.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-34294
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.

CVE-2022-23529
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

Sin descripción disponible.

CVE-2022-33705
Calendar General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-285 1 PoC

Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access calendar schedule without READ_CALENDAR permission.

CVE-2022-25263
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.

CVE-2022-25045
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Home Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.

CVE-2022-20141
Android General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In ip_check_mc_rcu of igmp.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege when opening and closing inet sockets with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-112551163References: Upstream kernel

CVE-2022-35899
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 4 PoCs

There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local user to escalate privileges by creating a %PROGRAMFILES(X86)%\ASUS\GameSDK.exe file.

CVE-2022-26495
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resulting in a write to a dangling pointer. This issue exists for the NBD_OPT_INFO, NBD_OPT_GO, and NBD_OPT_EXPORT_NAME messages.

CVE-2022-29952
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command and data protocols (60005/TCP, 60007/TCP) for communications between the monitoring controller and System 1 and/or Bently Nevada Monitor Configuration (BNMC) software. These protocols provide configuration management and historical data related functionality. Neither protocol has any authentication features, allowing any attacker capable of communicating with the ports in question to invoke (a subset of) desired functionality.

CVE-2022-28772
SAP NetWeaver (Internet Communication Manager) General
N/A
UNKNOWN
EPSS
1.1%
2022 CWE-121 1 PoC

By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions 7.53, 7.77, 7.81, 7.85, 7.86, or Internet Communication Manager - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, which makes these programs unavailable, leading to denial of service.

CVE-2022-25262
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.

CVE-2022-31661
VMware Workspace ONE Access, Identity Manager and vRealize Automation General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities. A malicious actor with local access can escalate privileges to 'root'.

CVE-2022-41197
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated VRML Worlds (.wrl, vrml.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-3168
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Sin descripción disponible.

CVE-2022-27669
SAP NetWeaver Application Server for Java General
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-862 1 PoC

An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access should be restricted. This may result in an escalation of privileges.

CVE-2022-25521
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

NUUO v03.11.00 was discovered to contain access control issue.