3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-35035
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b559f.

CVE-2022-22290
Samsung Internet General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-703 1 PoC

Incorrect download source UI in Downloads in Samsung Internet prior to 16.0.6.23 allows attackers to perform domain spoofing via a crafted HTML page.

CVE-2022-27630
LinkHub Mesh Wifi General
6.5
MEDIUM
EPSS
0.4%
2022 CWE-200 1 PoC

An information disclosure vulnerability exists in the confctl_get_master_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to information disclosure. An attacker can send packets to trigger this vulnerability.

CVE-2022-46695
tvOS General
6.5
MEDIUM
EPSS
0.8%
2022 5 PoCs

A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Visiting a website that frames malicious content may lead to UI spoofing.

CVE-2022-38750
SnakeYAML General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-121 1 PoC

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.

CVE-2022-31901
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two crafted files.

CVE-2022-35027
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fe9a7.

CVE-2022-31749
Fireware OS General
6.5
MEDIUM
EPSS
0.5%
2022 CWE-88 2 PoCs

An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.1.4, and 12.5.10 allows an authenticated remote attacker with unprivileged credentials to upload or read files to limited, arbitrary locations on WatchGuard Firebox and XTM appliances

CVE-2022-22754
Firefox General
6.5
MEDIUM
EPSS
0.0%
2022 2 PoCs

If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grants the new version the new requested permissions. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVE-2022-22783
Zoom On-Premise Meeting Connector Controller General
6.5
MEDIUM
EPSS
0.6%
2022 1 PoC

A vulnerability in Zoom On-Premise Meeting Connector Controller version 4.8.102.20220310 and On-Premise Meeting Connector MMR version 4.8.102.20220310 exposes process memory fragments to connected clients, which could be observed by a passive attacker.

CVE-2022-37424
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery.

CVE-2022-43771
Pentaho Business Analytics Server General
6.5
MEDIUM
EPSS
3.0%
2022 CWE-22 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x, using the Pentaho Data Access plugin exposes a service endpoint for CSV import which allows a user supplied path to access resources that are out of bounds.  

CVE-2022-31251
openSUSE Factory General
6.5
MEDIUM
EPSS
0.0%
2022 CWE-276 1 PoC

A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over the slurm user to escalate to root. This issue affects: openSUSE Factory slurm versions prior to 22.05.2-3.3.

CVE-2022-35034
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e7e3d.

CVE-2022-39183
Moodle Plugin - SAML Auth General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-601 1 PoC

Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.

CVE-2022-28761
Zoom On-Premise Meeting Connector MMR General
6.5
MEDIUM
EPSS
0.4%
2022 CWE-284 1 PoC

Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131 contains an improper access control vulnerability. As a result, a malicious actor in a meeting or webinar they are authorized to join could prevent participants from receiving audio and video causing meeting disruptions.

CVE-2022-35053
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x61731f.

CVE-2022-46377
uC-FTPs General
6.5
MEDIUM
EPSS
0.5%
2022 CWE-823 1 PoC

An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacker can send packets to trigger this vulnerability.This vulnerability occurs when no IP address argument is provided to the `PORT` command.

CVE-2022-27633
LinkHub Mesh Wifi General
6.5
MEDIUM
EPSS
0.5%
2022 CWE-200 1 PoC

An information disclosure vulnerability exists in the confctl_get_guest_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to information disclosure. An attacker can send packets to trigger this vulnerability.

CVE-2022-35066
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e41b8.