3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-32092
Software Genérico General
N/A
UNKNOWN
EPSS
22.5%
2022 1 PoC

D-Link DIR-645 v1.03 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter at __ajax_explorer.sgi.

CVE-2022-27223
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access.

CVE-2022-41192
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens manipulated Jupiter Tesselation (.jt, JTReader.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible for the application to crash and becomes temporarily unavailable to the user until restart of the application.

CVE-2022-22819
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2022 1 PoC

NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a buffer overflow in parsing SB2 updates before the signature is verified. This can allow an attacker to achieve non-persistent code execution via a crafted unsigned update.

CVE-2022-33989
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

dproxy-nexgen (aka dproxy nexgen) uses a static UDP source port (selected randomly only at boot time) in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.

CVE-2022-23377
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Archeevo below 5.0 is affected by local file inclusion through file=~/web.config to allow an attacker to retrieve local files.

CVE-2022-22531
SAP S/4HANA General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to run arbitrary script code, resulting in sensitive information being disclosed or modified.

CVE-2022-29612
SAP NetWeaver, ABAP Platform and SAP Host Agent General
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-918 1 PoC

SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, 8.04, SAPHOSTAGENT 7.22, allows an authenticated user to misuse a function of sapcontrol webfunctionality(startservice) in Kernel which enables malicious users to retrieve information. On successful exploitation, an attacker can obtain technical information like system number or physical address, which is otherwise restricted, causing a limited impact on the confidentiality of the application.

CVE-2022-26580
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2022 1 PoC

PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow the execution of specific command injections on selected binaries in the ADB daemon shell service. The attacker must have physical USB access to the device in order to exploit this vulnerability.

CVE-2022-41974
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.

CVE-2022-41850
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

roccat_report_event in drivers/hid/hid-roccat.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free in certain situations where a report is received while copying a report->value is in progress.

CVE-2022-24578
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

GPAC 1.0.1 is affected by a heap-based buffer overflow in SFS_AddString () at bifs/script_dec.c.

CVE-2022-24976
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a challenge-response login sequence.

CVE-2022-47673
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

An issue was discovered in Binutils addr2line before 2.39.3, function parse_module contains multiple out of bound reads which may cause a denial of service or other unspecified impacts.

CVE-2022-23345
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.

CVE-2022-36620
Software Genérico General
N/A
UNKNOWN
EPSS
3.8%
2022 1 PoC

D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.

CVE-2022-28991
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files.

CVE-2022-24346
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possible.

CVE-2022-35069
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b544e.

CVE-2022-24237
Software Genérico General
N/A
UNKNOWN
EPSS
23.4%
2022 1 PoC

The snaptPowered2 component of Snapt Aria v12.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands.