3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-24428
PowerScale OneFS General
6.3
MEDIUM
EPSS
0.3%
2022 CWE-281 1 PoC

Dell PowerScale OneFS, versions 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, and 9.3.0.x, contain an improper preservation of privileges. A remote filesystem user with a local account could potentially exploit this vulnerability, leading to an escalation of file privileges and information disclosure.

CVE-2022-36402
kernel General
6.3
MEDIUM
EPSS
0.1%
2022 CWE-118 1 PoC

An integer overflow vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).

CVE-2022-43848
AIX General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service. IBM X-Force ID: 239169.

CVE-2022-36837
Samsung email General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-285 1 PoC

Intent redirection vulnerability using implicit intent in Samsung email prior to version 6.1.70.20 allows attacker to get sensitive information.

CVE-2022-27842
Smart Switch PC General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

DLL hijacking vulnerability in Smart Switch PC prior to version 4.2.22022_4 allows attacker to execute abitrary code.

CVE-2022-25664
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables General
6.2
MEDIUM
EPSS
0.2%
2022 1 PoC

Information disclosure due to exposure of information while GPU reads the data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

CVE-2022-43380
AIX General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-399 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX NFS kernel extension to cause a denial of service. IBM X-Force ID: 238640.

CVE-2022-27843
Kies General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

DLL hijacking vulnerability in Kies prior to version 2.6.4.22014_2 allows attacker to execute abitrary code.

CVE-2022-42284
NVIDIA DGX servers General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-312 1 PoC

NVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credentials exposure.

CVE-2022-36830
Charm by Samsung General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-927 1 PoC

PendingIntent hijacking vulnerability in cancelAlarmManager in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.

CVE-2022-39186
BV-10 Performance Endpoint Unit General
6.2
MEDIUM
EPSS
0.0%
2022 1 PoC

EXFO - BV-10 Performance Endpoint Unit misconfiguration. System configuration file has misconfigured permissions

CVE-2022-39164
AIX General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-400 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 235181.

CVE-2022-33714
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1 allows attacker to reset a setting value related to mobile hotspot.

CVE-2022-33689
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unprotected binder call.

CVE-2022-28791
Galaxy Store General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a specific path. The patch adds proper protection to prevent overwrite to existing files.

CVE-2022-40233
AIX General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX TCP/IP kernel extension to cause a denial of service. IBM X-Force ID: 235599.

CVE-2022-30744
Samsung Kies General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arbitrary code.

CVE-2022-23998
Samsung Camera General
6.2
MEDIUM
EPSS
0.2%
2022 CWE-20 1 PoC

Improper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in Android P(9) allows untrusted applications to take a picture in screenlock status.

CVE-2022-33733
Charm by Samsung General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-927 1 PoC

Sensitive information exposure in onCharacteristicRead in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection information without permission.

CVE-2022-39165
AIX General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-400 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-Force ID: 235183.