3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-1972
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

Sin descripción disponible.

CVE-2022-1833
AMQ Broker Operator General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-276 1 PoC

A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where the AMQ Operator is deployed has access to clusterwide edit rights by checking the secrets. The service account used for building the Operator gives more permission than expected and an attacker could benefit from it. This requires at least an already compromised low-privilege account or insider attack.

CVE-2022-24574
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

GPAC 1.0.1 is affected by a NULL pointer dereference in gf_dump_vrml_field.isra ().

CVE-2022-30763
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

Janet before 1.22.0 mishandles arrays.

CVE-2022-29972
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift ODBC Driver (1.4.14 through 1.4.21.1001 and 1.4.22 through 1.4.x before 1.4.52) may allow a local user to execute arbitrary code.

CVE-2022-41172
SAP 3D Visual Enterprise Author General
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated AutoCAD (.dxf, TeighaTranslator.exe) file received from untrusted sources in SAP 3D Visual Enterprise Author - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVE-2022-26109
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.3%
2022 CWE-20 1 PoC

When a user opens a manipulated Portable Document Format (.pdf, PDFView.x3d) received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9.0, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-31209
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The firmware contains a potential buffer overflow by calling strcpy() without checking the string length beforehand.

CVE-2022-32450
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 3 PoCs

AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.

CVE-2022-27250
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

The UNISOC chipset through 2022-03-15 allows attackers to obtain remote control of a mobile phone, e.g., to obtain sensitive information from text messages or the device's screen, record video of the device's physical environment, or modify data.

CVE-2022-48565
Software Genérico General
N/A
UNKNOWN
EPSS
7.3%
2022 1 PoC

An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.

CVE-2022-37422
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2022 1 PoC

Payara through 5.2022.2 allows directory traversal without authentication. This affects Payara Server, Payara Micro, and Payara Server Embedded.

CVE-2022-26496
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by sending a crafted NBD_OPT_INFO or NBD_OPT_GO message with an large value as the length of the name.

CVE-2022-49248
Linux General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-lib: fix uninitialized flag for AV/C deferred transaction AV/C deferred transaction was supported at a commit 00a7bb81c20f ("ALSA: firewire-lib: Add support for deferred transaction") while 'deferrable' flag can be uninitialized for non-control/notify AV/C transactions. UBSAN reports it: kernel: ================================================================================ kernel: UBSAN: invalid-load in /build/linux-aa0B4d/linux-5.15.0/sound/firewire/fcp.c:363:9 kernel: load of value 158 is not a valid valu

CVE-2022-42722
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 2 PoCs

In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames into the mac80211 stack could cause a NULL pointer dereference denial-of-service attack against the beacon protection of P2P devices.

CVE-2022-32273
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

As a result of an observable discrepancy in returned messages, OPSWAT MetaDefender Core (MDCore) before 5.1.2 could allow an authenticated user to enumerate filenames on the server.

CVE-2022-26702
watchOS General
N/A
UNKNOWN
EPSS
0.6%
2022 1 PoC

A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 8.6, tvOS 15.5, iOS 15.5 and iPadOS 15.5. An application may be able to execute arbitrary code with kernel privileges.

CVE-2022-32564
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2022 2 PoCs

An issue was discovered in Couchbase Server before 7.0.4. In couchbase-cli, server-eshell leaks the Cluster Manager cookie.

CVE-2022-31205
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in memory area D1449...D1452 and can be read out using the Omron FINS protocol without any further authentication.

CVE-2022-30275
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to communicate with MOSCAD/ACE RTUs for engineering purposes. Access to these communications is protected by a password stored in cleartext in the wmdlcdrv.ini driver configuration file. In addition, this password is used for access control to MOSCAD/STS projects protected with the Legacy Password feature. In this case, an insecure CRC of the password is present in the project file: this CRC is validated against the password in the driver configuration file.