3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-0766
janeczku/calibre-web General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

CVE-2022-0524
publify/publify General
6.5
MEDIUM
EPSS
0.3%
2022 CWE-840 1 PoC

Business Logic Errors in GitHub repository publify/publify prior to 9.2.7.

CVE-2022-47924
csaf-validator-lib General
6.5
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

An high privileged attacker may pass crafted arguments to the validate function of csaf-validator-lib of a locally installed Secvisogram in versions < 0.1.0 wich can result in arbitrary code execution and DoS once the users triggers the validation.

CVE-2022-36317
Firefox General
6.5
MEDIUM
EPSS
0.3%
2022 2 PoCs

When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denial of Service.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 103.

CVE-2022-35042
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x4adb11.

CVE-2022-3044
Chrome General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

CVE-2022-22783
Zoom On-Premise Meeting Connector Controller General
6.5
MEDIUM
EPSS
0.6%
2022 1 PoC

A vulnerability in Zoom On-Premise Meeting Connector Controller version 4.8.102.20220310 and On-Premise Meeting Connector MMR version 4.8.102.20220310 exposes process memory fragments to connected clients, which could be observed by a passive attacker.

CVE-2022-22757
Firefox General
6.5
MEDIUM
EPSS
0.2%
2022 1 PoC

Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connect back locally to the user's browser to control it. <br>*This bug only affected Firefox when WebDriver was enabled, which is not the default configuration.*. This vulnerability affects Firefox < 97.

CVE-2022-25645
dset General
6.5
MEDIUM
EPSS
0.7%
2022 2 PoCs

All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.

CVE-2022-35060
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0a32.

CVE-2022-47881
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

Foxit PDF Reader and PDF Editor 11.2.1.53537 and earlier has an Out-of-Bounds Read vulnerability.

CVE-2022-0002
Intel(R) Processors General
6.5
MEDIUM
EPSS
0.7%
2022 1 PoC

Non-transparent sharing of branch predictor within a context in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

CVE-2022-40713
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2022 1 PoC

An issue was discovered in NOKIA 1350OMS R14.2. Multiple Relative Path Traversal issues exist in different specific endpoints via the file parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily.

CVE-2022-35023
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 2 PoCs

OTFCC commit 617837b was discovered to contain a segmentation violation via /lib/x86_64-linux-gnu/libc.so.6+0xbb384.

CVE-2022-43771
Pentaho Business Analytics Server General
6.5
MEDIUM
EPSS
3.0%
2022 CWE-22 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x, using the Pentaho Data Access plugin exposes a service endpoint for CSV import which allows a user supplied path to access resources that are out of bounds.  

CVE-2022-35052
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b84b1.

CVE-2022-35043
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2022 1 PoC

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c08a6.

CVE-2022-3269
ikus060/rdiffweb General
6.4
MEDIUM
EPSS
0.4%
2022 CWE-384 1 PoC

Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7.

CVE-2022-23540
node-jsonwebtoken General
6.4
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass due to defaulting to the `none` algorithm for signature verification. Users are affected if you do not specify algorithms in the `jwt.verify()` function. This issue has been fixed, please update to version 9.0.0 which removes the default support for the none algorithm in the `jwt.verify()` method. There will be no impact, if you update to version 9.0.0 and you don’t need to allow for the `none` algorithm. If you need 'none' algorithm, you have to

CVE-2022-39854
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory.