3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-2946
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0246.

CVE-2022-46694
tvOS General
7.8
HIGH
EPSS
0.2%
2022 4 PoCs

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2, tvOS 16.2, watchOS 9.2. Parsing a maliciously crafted video file may lead to kernel code execution.

CVE-2022-43701
Arm Compiler 5 (AC5), Arm Compiler for Embedded 6 (AC6), Fast Models (FM), Arm Compiler for Embedded FuSA (ACEF), Arm Development Studio (ADS), Arm Forge (AF), Arm Mobile Studio (AMS), DS-5 Development Studio, Fast Models (FM), GNU Toolchain (GT), Keil MDK (KMDK), Mbed Studio (MS) General
7.8
HIGH
EPSS
0.1%
2022 CWE-276 1 PoC

When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code.

CVE-2022-23946
KiCad General
7.8
HIGH
EPSS
0.5%
2022 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-24367
PDF Reader General
7.8
HIGH
EPSS
0.7%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15877.

CVE-2022-38691
SC9863A//T310/T610/T618/ General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

In BootROM, there is a possible missing validation for Certificate Type 0. This could lead to local escalation of privilege with no additional execution privileges needed.

CVE-2022-43310
Software Genérico General
7.8
HIGH
EPSS
0.0%
2022 1 PoC

An Uncontrolled Search Path Element in Foxit Software released Foxit Reader v11.2.118.51569 allows attackers to escalate privileges when searching for DLL libraries without specifying an absolute path.

CVE-2022-41307
Subassembly Composer General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

CVE-2022-3297
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0579.

CVE-2022-36443
Software Genérico General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The device allows the administrator to lock some communication channels (wireless and SD card) but it is still possible to use a physical connection (Ethernet cable) without restriction.

CVE-2022-3699
HardwareScanPlugin General
7.8
HIGH
EPSS
85.1%
2022 CWE-787 2 PoCs

A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45 that could allow a local user to execute code with elevated privileges.

CVE-2022-3234
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.

CVE-2022-2183
vim/vim General
7.8
HIGH
EPSS
0.6%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

CVE-2022-1427
mruby/mruby General
7.7
HIGH
EPSS
0.3%
2022 CWE-125 1 PoC

Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary code execution if being exploited.

CVE-2022-25301
jsgui-lang-essentials General
7.7
HIGH
EPSS
0.4%
2022 1 PoC

All versions of package jsgui-lang-essentials are vulnerable to Prototype Pollution due to allowing all Object attributes to be altered, including their magical attributes such as proto, constructor and prototype.

CVE-2022-42275
NVIDIA DGX servers General
7.7
HIGH
EPSS
0.0%
2022 CWE-288 1 PoC

NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. This may lead to a loss of integrity and denial of service.

CVE-2022-27838
FactoryCamera General
7.7
HIGH
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with system privilege.

CVE-2022-35978
minetest General
7.7
HIGH
EPSS
13.7%
2022 CWE-693 1 PoC

Minetest is a free open-source voxel game engine with easy modding and game creation. In **single player**, a mod can set a global setting that controls the Lua script loaded to display the main menu. The script is then loaded as soon as the game session is exited. The Lua environment the menu runs in is not sandboxed and can directly interfere with the user's system. There are currently no known workarounds.

CVE-2022-1213
livehelperchat/livehelperchat General
7.7
HIGH
EPSS
0.1%
2022 CWE-918 1 PoC

SSRF filter bypass port 80, 433 in GitHub repository livehelperchat/livehelperchat prior to 3.67v. An attacker could make the application perform arbitrary requests, bypass CVE-2022-1191

CVE-2022-25647
com.google.code.gson:gson General
7.7
HIGH
EPSS
2.8%
2022 1 PoC

The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.