3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-0586
Wireshark General
6.3
MEDIUM
EPSS
0.0%
2022 1 PoC

Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

CVE-2022-4857
Modbus Poll General
6.3
MEDIUM
EPSS
0.3%
2022 CWE-120 1 PoC

A vulnerability was found in Modbus Tools Modbus Poll up to 9.10.0 and classified as critical. Affected by this issue is some unknown functionality of the file mbpoll.exe of the component mbp File Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-217022 is the identifier assigned to this vulnerability.

CVE-2022-0518
radareorg/radare2 General
6.3
MEDIUM
EPSS
0.4%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2.

CVE-2022-3970
LibTIFF General
6.3
MEDIUM
EPSS
0.1%
2022 CWE-189 1 PoC

A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to fix this issue. The identifier VDB-213549 was assigned to this vulnerability.

CVE-2022-45097
PowerScale OneFS General
6.3
MEDIUM
EPSS
0.3%
2022 CWE-842 1 PoC

Dell PowerScale OneFS 9.0.0.x-9.4.0.x contains an Incorrect User Management vulnerability. A low privileged network attacker could potentially exploit this vulnerability, leading to escalation of privileges, and information disclosure.

CVE-2022-1211
Furnace General
6.3
MEDIUM
EPSS
0.3%
2022 CWE-121 1 PoC

A vulnerability classified as critical has been found in tildearrow Furnace dev73. This affects the FUR to VGM converter in console mode which causes stack-based overflows and crashes. It is possible to initiate the attack remotely but it requires user-interaction. A POC has been disclosed to the public and may be used.

CVE-2022-3784
Bento4 General
6.3
MEDIUM
EPSS
0.4%
2022 CWE-119 1 PoC

A vulnerability classified as critical was found in Axiomatic Bento4 5e7bb34. Affected by this vulnerability is the function AP4_Mp4AudioDsiParser::ReadBits of the file Ap4Mp4AudioInfo.cpp of the component mp4hls. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212563.

CVE-2022-33931
Wyse Management Suite General
6.3
MEDIUM
EPSS
0.3%
2022 CWE-284 1 PoC

Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An attacker with no access to Alert Classification page could potentially exploit this vulnerability, leading to the change the alert categories.

CVE-2022-40133
kernel General
6.3
MEDIUM
EPSS
0.0%
2022 CWE-416 1 PoC

A use-after-free(UAF) vulnerability was found in function 'vmw_execbuf_tie_context' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).

CVE-2022-21820
NVIDIA Data Center GPU Manager General
6.3
MEDIUM
EPSS
1.2%
2022 CWE-20 1 PoC

NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions without action, which may lead to limited code execution, some denial of service, escalation of privileges, and limited impacts to both data confidentiality and integrity.

CVE-2022-3492
Human Resource Management System General
6.3
MEDIUM
EPSS
1.0%
2022 CWE-707 1 PoC

A vulnerability classified as critical was found in SourceCodester Human Resource Management System 1.0. This vulnerability affects unknown code of the component Profile Photo Handler. The manipulation of the argument parameter leads to os command injection. The attack can be initiated remotely. The identifier of this vulnerability is VDB-210772.

CVE-2022-3960
Pentaho Business Analytics Server General
6.3
MEDIUM
EPSS
0.6%
2022 CWE-96 1 PoC

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of the Community Dashboard Editor (CDE) plugin. 

CVE-2022-38096
kernel General
6.3
MEDIUM
EPSS
0.0%
2022 CWE-476 2 PoCs

A NULL pointer dereference vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).

CVE-2022-0178
snipe/snipe-it General
6.3
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8.

CVE-2022-0519
radareorg/radare2 General
6.3
MEDIUM
EPSS
0.4%
2022 CWE-805 1 PoC

Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2.

CVE-2022-0179
snipe/snipe-it General
6.3
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

snipe-it is vulnerable to Missing Authorization

CVE-2022-2980
vim/vim General
6.3
MEDIUM
EPSS
0.1%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0259.

CVE-2022-0522
radareorg/radare2 General
6.3
MEDIUM
EPSS
0.4%
2022 CWE-786 1 PoC

Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2.

CVE-2022-34769
Michlol - rashim web General
6.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Michlol - rashim web interface Insecure direct object references (IDOR). First of all, the attacker needs to login. After he performs log into the system there are some functionalities that the specific user is not allowed to perform. However all the attacker needs to do in order to achieve his goals is to change the value of the ptMsl parameter and then the attacker can access sensitive data that he not supposed to access because its belong to another user.

CVE-2022-0611
snipe/snipe-it General
6.3
MEDIUM
EPSS
0.3%
2022 CWE-862 1 PoC

Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11.