3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-39886
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-280 1 PoC

Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022 Release 1 allows local attacker to access Device information.

CVE-2022-45480
PC Keyboard WiFi & Bluetooth General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-319 1 PoC

PC Keyboard WiFi & Bluetooth allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2022-36867
Editor Lite General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in Editor Lite prior to version 4.0.40.14 allows attackers to access sensitive information.

CVE-2022-26099
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

Null pointer dereference vulnerability in parser_infe function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds read by remote attackers.

CVE-2022-43595
OpenImageIO General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-476 1 PoC

Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .fits files.

CVE-2022-43704
Software Genérico General
5.9
MEDIUM
EPSS
1.6%
2022 2 PoCs

The Sinilink XY-WFT1 WiFi Remote Thermostat, running firmware 1.3.6, allows an attacker to bypass the intended requirement to communicate using MQTT. It is possible to replay Sinilink aka SINILINK521 protocol (udp/1024) commands interfacing directly with the target device. This, in turn, allows for an attack to control the onboard relay without requiring authentication via the mobile application. This might result in an unacceptable temperature within the target device's physical environment.

CVE-2022-0712
radareorg/radare2 General
5.9
MEDIUM
EPSS
0.4%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4.

CVE-2022-26097
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

Null pointer dereference vulnerability in parser_unknown_property function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

CVE-2022-28776
Galaxy Store General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-285 1 PoC

Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications from Galaxy Store without user interactions.

CVE-2022-39876
Reminder General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-532 1 PoC

Insertion of Sensitive Information into Log in PushRegIdUpdateClient of SReminder prior to 8.2.01.13 allows attacker to access device IMEI.

CVE-2022-43594
OpenImageIO General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-476 1 PoC

Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can provide malicious multiple inputs to trigger these vulnerabilities.This vulnerability applies to writing .bmp files.

CVE-2022-34716
Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) General
5.9
MEDIUM
EPSS
1.0%
2022 1 PoC

.NET Spoofing Vulnerability

CVE-2022-0419
radareorg/radare2 General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.

CVE-2022-36873
com.samsung.android.waterplugin General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.22081151 leaks MAC address of the connected Bluetooth device.

CVE-2022-39861
FactoryCamera General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

Unprotected Receiver in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to record video without camera privilege.

CVE-2022-25897
org.eclipse.milo:sdk-server General
5.9
MEDIUM
EPSS
0.3%
2022 1 PoC

The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

CVE-2022-33729
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

Improper restriction of broadcasting Intent in ConfirmConnectActivity of?NFC prior to SMR Aug-2022 Release 1 leaks MAC address of the connected Bluetooth device.

CVE-2022-1929
devcert General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-1333 1 PoC

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method

CVE-2022-22464
Security Verify Access General
5.9
MEDIUM
EPSS
0.1%
2022 1 PoC

IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225081.

CVE-2022-36861
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-269 1 PoC

Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI privilege.