3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-2301
hpjansson/chafa General
5.5
MEDIUM
EPSS
0.3%
2022 CWE-126 1 PoC

Buffer Over-read in GitHub repository hpjansson/chafa prior to 1.10.3.

CVE-2022-2056
libtiff General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.

CVE-2022-3106
Kernel General
5.5
MEDIUM
EPSS
0.1%
2022 CWE-476 1 PoC

An issue was discovered in the Linux kernel through 5.16-rc6. ef100_update_stats in drivers/net/ethernet/sfc/ef100_nic.c lacks check of the return value of kmalloc().

CVE-2022-43071
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

CVE-2022-42853
macOS General
5.5
MEDIUM
EPSS
0.2%
2022 1 PoC

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Ventura 13.1. An app may be able to modify protected parts of the file system.

CVE-2022-4415
systemd General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-200 2 PoCs

A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.

CVE-2022-0326
mruby/mruby General
5.5
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

NULL Pointer Dereference in Homebrew mruby prior to 3.2.

CVE-2022-48303
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2022 1 PoC

GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.

CVE-2022-35098
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via GfxICCBasedColorSpace::getDefaultColor(GfxColor*) at /xpdf/GfxState.cc.

CVE-2022-41218
Software Genérico General
5.5
MEDIUM
EPSS
0.4%
2022 4 PoCs

In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release.

CVE-2022-0762
microweber/microweber General
5.5
MEDIUM
EPSS
0.2%
2022 CWE-863 1 PoC

Incorrect Authorization in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-39845
Samsung Kies General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-354 1 PoC

Improper validation of integrity check vulnerability in Samsung Kies prior to version 2.6.4.22074 allows local attackers to delete arbitrary directory using directory junction.

CVE-2022-25814
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-276 1 PoC

PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.

CVE-2022-4964
Ubuntu pipewire-pulse General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.

CVE-2022-41842
Software Genérico General
5.5
MEDIUM
EPSS
0.3%
2022 1 PoC

An issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc.

CVE-2022-3626
libtiff General
5.5
MEDIUM
EPSS
0.0%
2022 1 PoC

LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c:340 when called from processCropSelections, tools/tiffcrop.c:7619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191.

CVE-2022-39253
git General
5.5
MEDIUM
EPSS
2.6%
2022 CWE-200 1 PoC

Git is an open source, scalable, distributed revision control system. Versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4 are subject to exposure of sensitive information to a malicious actor. When performing a local clone (where the source and target of the clone are on the same volume), Git copies the contents of the source's `$GIT_DIR/objects` directory into the destination by either creating hardlinks to the source contents, or copying them (if hardlinks are disabled via `--no-hardlinks`). A malicious actor could convince a victim to clone a repository with

CVE-2022-44318
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StringStrcat function in cstdlib/string.c when called from ExpressionParseFunctionCall.

CVE-2022-1771
vim/vim General
5.5
MEDIUM
EPSS
0.1%
2022 CWE-674 1 PoC

Uncontrolled Recursion in GitHub repository vim/vim prior to 8.2.4975.