3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-24404
TETRA Standard General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-353 1 PoC

Lack of cryptographic integrity check on TETRA air-interface encrypted traffic. Since a stream cipher is employed, this allows an active adversary to manipulate cleartext data in a bit-by-bit fashion.

CVE-2022-2596
node-fetch/node-fetch General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-1333 1 PoC

Inefficient Regular Expression Complexity in GitHub repository node-fetch/node-fetch prior to 3.2.10.

CVE-2022-1286
mruby/mruby General
5.9
MEDIUM
EPSS
0.6%
2022 CWE-122 1 PoC

heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

CVE-2022-22401
Aspera Faspex General
5.9
MEDIUM
EPSS
0.0%
2022 1 PoC

IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather or persuade a naive user to supply sensitive information. IBM X-Force ID: 222567.

CVE-2022-40693
SDS-3008 Series Industrial Ethernet Switch General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-319 2 PoCs

A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.

CVE-2022-21211
posix General
5.9
MEDIUM
EPSS
0.4%
2022 1 PoC

This affects all versions of package posix. When invoking the toString method, it will fallback to 0x0 value, as the value of toString is not invokable (not a function), and then it will crash with type-check.

CVE-2022-43592
OpenImageIO General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-125 1 PoC

An information disclosure vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability.

CVE-2022-26096
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.4%
2022 CWE-476 1 PoC

Null pointer dereference vulnerability in parser_ispe function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

CVE-2022-42964
pymatgen General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-1333 1 PoC

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the pymatgen PyPI package, when an attacker is able to supply arbitrary input to the GaussianInput.from_string method

CVE-2022-1930
eth-account General
5.9
MEDIUM
EPSS
0.3%
2022 CWE-1333 1 PoC

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the eth-account PyPI package, when an attacker is able to supply arbitrary input to the encode_structured_data method

CVE-2022-33729
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

Improper restriction of broadcasting Intent in ConfirmConnectActivity of?NFC prior to SMR Aug-2022 Release 1 leaks MAC address of the connected Bluetooth device.

CVE-2022-30735
Samsung Account General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_token without permission.

CVE-2022-36868
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

Improper restriction of broadcasting Intent in MouseNKeyHidDevice prior to SMR Oct-2022 Release 1 leaks MAC address of the connected Bluetooth device.

CVE-2022-24928
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-815 1 PoC

Security misconfiguration of RKP in kernel prior to SMR Mar-2022 Release 1 allows a system not to be protected by RKP.

CVE-2022-39872
ShareLive General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-280 1 PoC

Improper restriction of broadcasting Intent in ShareLive prior to version 13.2.03.5 leaks MAC address of the connected Bluetooth device.

CVE-2022-43593
OpenImageIO General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-476 1 PoC

A denial of service vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to null pointer dereference. An attacker can provide malicious input to trigger this vulnerability.

CVE-2022-43596
OpenImageIO General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-125 1 PoC

An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability.

CVE-2022-36861
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-269 1 PoC

Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI privilege.

CVE-2022-45483
Lazy Mouse General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-319 1 PoC

Lazy Mouse allows an attacker (in a man in the middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2022-0631
mruby/mruby General
5.9
MEDIUM
EPSS
0.3%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.