3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-35027
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fe9a7.

CVE-2022-31251
openSUSE Factory General
6.5
MEDIUM
EPSS
0.0%
2022 CWE-276 1 PoC

A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over the slurm user to escalate to root. This issue affects: openSUSE Factory slurm versions prior to 22.05.2-3.3.

CVE-2022-39902
Samsung Mobile Devices General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-285 1 PoC

Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive information including IMEI via emergency call.

CVE-2022-35034
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e7e3d.

CVE-2022-0277
microweber/microweber General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-732 1 PoC

Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-28761
Zoom On-Premise Meeting Connector MMR General
6.5
MEDIUM
EPSS
0.4%
2022 CWE-284 1 PoC

Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131 contains an improper access control vulnerability. As a result, a malicious actor in a meeting or webinar they are authorized to join could prevent participants from receiving audio and video causing meeting disruptions.

CVE-2022-31749
Fireware OS General
6.5
MEDIUM
EPSS
0.5%
2022 CWE-88 2 PoCs

An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.1.4, and 12.5.10 allows an authenticated remote attacker with unprivileged credentials to upload or read files to limited, arbitrary locations on WatchGuard Firebox and XTM appliances

CVE-2022-35053
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x61731f.

CVE-2022-31901
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two crafted files.

CVE-2022-27633
LinkHub Mesh Wifi General
6.5
MEDIUM
EPSS
0.5%
2022 CWE-200 1 PoC

An information disclosure vulnerability exists in the confctl_get_guest_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to information disclosure. An attacker can send packets to trigger this vulnerability.

CVE-2022-0639
unshiftio/url-parse General
6.5
MEDIUM
EPSS
0.0%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.

CVE-2022-29916
Thunderbird General
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the browser history. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

CVE-2022-46377
uC-FTPs General
6.5
MEDIUM
EPSS
0.5%
2022 CWE-823 1 PoC

An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacker can send packets to trigger this vulnerability.This vulnerability occurs when no IP address argument is provided to the `PORT` command.

CVE-2022-24865
humhub General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-200 1 PoC

HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrieve other users' data. This issue has been resolved by commit `eb83de20`. It is recommended that the HumHub is upgraded to 1.11.0, 1.10.4 or 1.9.4. There are no known workarounds for this issue.

CVE-2022-38749
SnakeYAML General
6.5
MEDIUM
EPSS
0.5%
2022 CWE-121 1 PoC

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.

CVE-2022-0514
crater-invoice/crater General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-840 1 PoC

Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5.

CVE-2022-0950
star7th/showdoc General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-1511
snipe/snipe-it General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.

CVE-2022-35050
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b04de.

CVE-2022-0815
McAfee WebAdvisor General
6.5
MEDIUM
EPSS
0.4%
2022 CWE-668 1 PoC

Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain access to McAfee WebAdvisor settings and other details about the user’s system. This could lead to unexpected behaviors including; settings being changed, fingerprinting of the system leading to targeted scams, and not triggering the malicious software if McAfee software is detected.