3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-46377
uC-FTPs General
6.5
MEDIUM
EPSS
0.5%
2022 CWE-823 1 PoC

An out-of-bounds read vulnerability exists in the PORT command parameter extraction functionality of Weston Embedded uC-FTPs v 1.98.00. A specially-crafted set of network packets can lead to denial of service. An attacker can send packets to trigger this vulnerability.This vulnerability occurs when no IP address argument is provided to the `PORT` command.

CVE-2022-45914
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2022 3 PoCs

The ESL (Electronic Shelf Label) protocol, as implemented by (for example) the OV80e934802 RF transceiver on the ETAG-2130-V4.3 20190629 board, does not use authentication, which allows attackers to change label values via 433 MHz RF signals, as demonstrated by disrupting the organization of a hospital storage unit, or changing retail pricing.

CVE-2022-47874
Software Genérico General
6.5
MEDIUM
EPSS
22.1%
2022 1 PoC

Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class 'com.jedox.etl.mngr.Connections' and method 'getGlobalConnection'.

CVE-2022-30614
Cognos Analytics General
6.5
MEDIUM
EPSS
1.3%
2022 1 PoC

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 227591.

CVE-2022-38751
SnakeYAML General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-121 1 PoC

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow.

CVE-2022-1233
medialize/uri.js General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-115 1 PoC

URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11.

CVE-2022-28199
NVIDIA FLARE General
6.5
MEDIUM
EPSS
1.0%
2022 CWE-1284 1 PoC

NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.

CVE-2022-45895
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx in some situations) and the WhoAmI endpoint (e.g., path disclosure).

CVE-2022-35054
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6171b2.

CVE-2022-22290
Samsung Internet General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-703 1 PoC

Incorrect download source UI in Downloads in Samsung Internet prior to 16.0.6.23 allows attackers to perform domain spoofing via a crafted HTML page.

CVE-2022-25818
Samsung Mobile Devices General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-20 1 PoC

Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution.

CVE-2022-3869
froxlor/froxlor General ⚡ nuclei
6.5
MEDIUM
EPSS
14.9%
2022 CWE-94 1 PoC

Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2.

CVE-2022-25313
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2022 4 PoCs

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

CVE-2022-35029
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6babea.

CVE-2022-0524
publify/publify General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-840 1 PoC

Business Logic Errors in GitHub repository publify/publify prior to 9.2.7.

CVE-2022-46875
Firefox General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.

CVE-2022-35068
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e420d.

CVE-2022-39183
Moodle Plugin - SAML Auth General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-601 1 PoC

Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.

CVE-2022-26135
Jira Core Server General
6.5
MEDIUM
EPSS
89.3%
2022 1 PoC

A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version 8.13.22, from version 8.14.0 before 8.20.10, from version 8.21.0 before 8.22.4. This also affects Jira Management Server and Data Center versions from version 4.0.0 before 4.13.22, from version 4.14.0 before 4.20.10 and from version 4.21.0 before 4.22.4.

CVE-2022-35044
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x617087.