3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-37331
Open Babel General
7.3
HIGH
EPSS
0.1%
2022 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the Gaussian format orientation functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-1061
radareorg/radare2 General
7.3
HIGH
EPSS
0.3%
2022 CWE-122 1 PoC

Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8.

CVE-2022-32543
Alyac General
7.3
HIGH
EPSS
0.2%
2022 CWE-680 1 PoC

An integer overflow vulnerability exists in the way ESTsoft Alyac 2.5.8.544 parses OLE files. A specially-crafted OLE file can lead to a heap buffer overflow which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-4173
Avast and AVG Antivirus General
7.3
HIGH
EPSS
0.2%
2022 CWE-269 1 PoC

A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avast and AVG Antivirus version 22.10.

CVE-2022-0849
radareorg/radare2 General
7.3
HIGH
EPSS
0.3%
2022 CWE-416 1 PoC

Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6.

CVE-2022-3662
Bento4 General
7.3
HIGH
EPSS
0.4%
2022 CWE-119 1 PoC

A vulnerability was found in Axiomatic Bento4. It has been declared as critical. This vulnerability affects the function GetOffset of the file Ap4Sample.h of the component mp42hls. The manipulation leads to use after free. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-212002 is the identifier assigned to this vulnerability.

CVE-2022-22521
Benchmark Programming Tool General
7.3
HIGH
EPSS
0.1%
2022 CWE-732 2 PoCs

In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administrative privileges to execute these binaries as admin.

CVE-2022-0272
detekt/detekt General
7.3
HIGH
EPSS
0.3%
2022 CWE-611 1 PoC

Improper Restriction of XML External Entity Reference in GitHub repository detekt/detekt prior to 1.20.0.

CVE-2022-1621
vim/vim General
7.3
HIGH
EPSS
0.1%
2022 CWE-122 2 PoCs

Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution

CVE-2022-1295
alvarotrigo/fullpage.js General
7.3
HIGH
EPSS
0.6%
2022 CWE-1321 1 PoC

Prototype Pollution in GitHub repository alvarotrigo/fullpage.js prior to 4.0.2.

CVE-2022-2580
vim/vim General
7.3
HIGH
EPSS
0.0%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0102.

CVE-2022-42201
Software Genérico General
7.2
HIGH
EPSS
0.4%
2022 1 PoC

Simple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload.

CVE-2022-23155
Wyse Management Suite General
7.2
HIGH
EPSS
0.7%
2022 CWE-434 1 PoC

Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with admin privileges can exploit this vulnerability in order to execute arbitrary code on the system.

CVE-2022-41001
QUARTZ-GOLD General
7.2
HIGH
EPSS
3.5%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'icmp check link WORD destination WORD interval <1-255> retries <1-255> description (WORD|null)' command template.

CVE-2022-41000
QUARTZ-GOLD General
7.2
HIGH
EPSS
3.5%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'no gre index <1-8> tunnel A.B.C.D source (A.B.C.D|null) dest A.B.C.D keepalive (on|off) interval (<0-255>|null) retry (<0-255>|null) description (WORD|null)' command template.

CVE-2022-0242
crater-invoice/crater General
7.2
HIGH
EPSS
0.5%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.

CVE-2022-1032
crater-invoice/crater General
7.2
HIGH
EPSS
0.4%
2022 CWE-502 1 PoC

Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.

CVE-2022-40993
QUARTZ-GOLD General
7.2
HIGH
EPSS
1.4%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'firmwall keyword WORD description (WORD|null)' command template.