3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-37706
Software Genérico General
7.8
HIGH
EPSS
56.2%
2022 9 PoCs

enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and the system library function mishandles pathnames that begin with a /dev/.. substring.

CVE-2022-1898
vim/vim General
7.8
HIGH
EPSS
0.3%
2022 CWE-416 2 PoCs

Use After Free in GitHub repository vim/vim prior to 8.2.

CVE-2022-3016
vim/vim General
7.8
HIGH
EPSS
0.0%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0286.

CVE-2022-2289
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.

CVE-2022-30426
Software Genérico General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

There is a stack buffer overflow vulnerability, which could lead to arbitrary code execution in UEFI DXE driver on some Acer products. An attack could exploit this vulnerability to escalate privilege from ring 3 to ring 0, and hijack control flow during UEFI DXE execution. This affects Altos T110 F3 firmware version <= P13 (latest) and AP130 F2 firmware version <= P04 (latest) and Aspire 1600X firmware version <= P11.A3L (latest) and Aspire 1602M firmware version <= P11.A3L (latest) and Aspire 7600U firmware version <= P11.A4 (latest) and Aspire MC605 firmware version <= P11.A4L (latest) and A

CVE-2022-3328
snapd General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

Race condition in snap-confine's must_mkdir_and_open_with_perms()

CVE-2022-3352
vim/vim General
7.8
HIGH
EPSS
0.0%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0614.

CVE-2022-41199
SAP 3D Visual Enterprise Viewer General
7.8
HIGH
EPSS
1.8%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated Open Inventor File (.iv, vrml.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVE-2022-38928
Software Genérico General
7.8
HIGH
EPSS
0.2%
2022 1 PoC

XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.

CVE-2022-3155
Thunderbird General
7.8
HIGH
EPSS
0.0%
2022 1 PoC

When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was started immediately without asking the user to confirm. This vulnerability affects Thunderbird < 102.3.

CVE-2022-24356
PDF Reader General
7.8
HIGH
EPSS
0.7%
2022 CWE-125 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader Foxit reader 11.0.1.0719 macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the OnMouseExit method. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14848.

CVE-2022-32907
iOS General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

This issue was addressed with improved checks. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.

CVE-2022-37197
Software Genérico General
7.8
HIGH
EPSS
0.5%
2022 1 PoC

IOBit IOTransfer V4 is vulnerable to Unquoted Service Path.

CVE-2022-41034
Visual Studio Code General
7.8
HIGH
EPSS
63.2%
2022 1 PoC

Visual Studio Code Remote Code Execution Vulnerability

CVE-2022-2816
vim/vim General
7.8
HIGH
EPSS
0.0%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212.

CVE-2022-42899
Software Genérico General
7.8
HIGH
EPSS
0.7%
2022 1 PoC

Bentley MicroStation and MicroStation-based applications may be affected by out-of-bounds read and stack overflow issues when opening crafted SKP files. Exploiting these issues could lead to information disclosure and code execution. The fixed versions are 10.17.01.58* for MicroStation and 10.17.01.19* for Bentley View.

CVE-2022-28637
HPE Integrated Lights-Out 5 (iLO 5) General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

A local Denial of Service (DoS) and local arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses these security vulnerabilities.

CVE-2022-1942
vim/vim General
7.8
HIGH
EPSS
1.4%
2022 CWE-122 2 PoCs

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVE-2022-3699
HardwareScanPlugin General
7.8
HIGH
EPSS
85.1%
2022 CWE-787 2 PoCs

A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45 that could allow a local user to execute code with elevated privileges.