3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-41956
Autolab General
6.5
MEDIUM
EPSS
0.4%
2022 CWE-22 1 PoC

Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that enables instructors to offer autograded programming assignments to their students over the Web. A file disclosure vulnerability was discovered in Autolab's remote handin feature, whereby users are able to hand-in assignments using paths outside their submission directory. Users can then view the submission to view the file's contents. The vulnerability has been patched in version 2.10.0. As a workaround, ensure that the field for the remote handin feature is empty (Edit Assessm

CVE-2022-35022
Software Genérico General
6.5
MEDIUM
EPSS
0.5%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6badae.

CVE-2022-35048
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b0b2c.

CVE-2022-35061
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e412a.

CVE-2022-0639
unshiftio/url-parse General
6.5
MEDIUM
EPSS
0.0%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.

CVE-2022-2402
ESET Endpoint Encryption General
6.5
MEDIUM
EPSS
0.1%
2022 CWE-121 2 PoCs

The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kernel stack overflow, resulting in a system crash, for instance, a BSOD.

CVE-2022-35055
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0473.

CVE-2022-20361
Android General
6.5
MEDIUM
EPSS
1.5%
2022 1 PoC

In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakness in Bluetooth Standard. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-231161832

CVE-2022-35040
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b5567.

CVE-2022-35030
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fe954.

CVE-2022-35038
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b064d.

CVE-2022-24729
ckeditor4 General
6.5
MEDIUM
EPSS
0.8%
2022 CWE-400 2 PoCs

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0. There are currently no known workarounds.

CVE-2022-4868
froxlor/froxlor General
6.5
MEDIUM
EPSS
0.2%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

CVE-2022-0623
mruby/mruby General
6.5
MEDIUM
EPSS
0.4%
2022 CWE-125 1 PoC

Out-of-bounds Read in Homebrew mruby prior to 3.2.

CVE-2022-3044
Chrome General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

CVE-2022-0766
janeczku/calibre-web General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

CVE-2022-0691
unshiftio/url-parse General
6.5
MEDIUM
EPSS
0.1%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.

CVE-2022-47924
csaf-validator-lib General
6.5
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

An high privileged attacker may pass crafted arguments to the validate function of csaf-validator-lib of a locally installed Secvisogram in versions < 0.1.0 wich can result in arbitrary code execution and DoS once the users triggers the validation.

CVE-2022-36317
Firefox General
6.5
MEDIUM
EPSS
0.3%
2022 2 PoCs

When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denial of Service.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 103.

CVE-2022-1196
Thunderbird General
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8 and Firefox ESR < 91.8.