3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-36442
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

An issue was discovered in Zebra Enterprise Home Screen 4.1.19. By using the embedded Google Chrome application, it is possible to install an unauthorized application via a downloaded APK.

CVE-2022-39844
Smart Switch PC General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-354 1 PoC

Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.22083 allows local attackers to delete arbitrary directory using directory junction.

CVE-2022-32755
Security Directory Server General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-91 1 PoC

IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 228505.

CVE-2022-42866
tvOS General
5.5
MEDIUM
EPSS
0.1%
2022 4 PoCs

The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, watchOS 9.2. An app may be able to read sensitive location information.

CVE-2022-40363
Software Genérico General
5.5
MEDIUM
EPSS
0.2%
2022 1 PoC

A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cause a Denial of Service (DoS) via a crafted NFC file.

CVE-2022-35080
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_load at /lib/png.c.

CVE-2022-40884
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

Bento4 1.6.0 has memory leaks via the mp4fragment.

CVE-2022-3112
Kernel General
5.5
MEDIUM
EPSS
0.1%
2022 CWE-476 1 PoC

An issue was discovered in the Linux kernel through 5.16-rc6. amvdec_set_canvases in drivers/staging/media/meson/vdec/vdec_helpers.c lacks check of the return value of kzalloc() and will cause the null pointer dereference.

CVE-2022-35099
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

SWFTools commit 772e55a2 was discovered to contain a stack overflow via ImageStream::getPixel(unsigned char*) at /xpdf/Stream.cc.

CVE-2022-34392
SupportAssist General
5.5
MEDIUM
EPSS
0.1%
2022 CWE-613 1 PoC

SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An authenticated non-admin user can be able to obtain the refresh token and that leads to reuse the access token and fetch sensitive information.

CVE-2022-49441
Linux General
5.5
MEDIUM
EPSS
0.0%
2022 1 PoC

In the Linux kernel, the following vulnerability has been resolved: tty: fix deadlock caused by calling printk() under tty_port->lock pty_write() invokes kmalloc() which may invoke a normal printk() to print failure message. This can cause a deadlock in the scenario reported by syz-bot below: CPU0 CPU1 CPU2 ---- ---- ---- lock(console_owner); lock(&port_lock_key); lock(&port->lock); lock(&port_lock_key);

CVE-2022-39836
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 2 PoCs

An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a heap-based buffer over-read of one byte.

CVE-2022-2752
GateManager General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

A vulnerability in the web server of Secomea GateManager allows a local user to impersonate as the previous user under some failed login conditions. This issue affects: Secomea GateManager versions from 9.4 through 9.7.

CVE-2022-1507
hpjansson/chafa General
5.5
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file. in GitHub repository hpjansson/chafa prior to 1.10.2. chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file.

CVE-2022-35089
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

SWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor at /home/bupt/Desktop/swftools/src/gif2swf.

CVE-2022-32827
macOS General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to cause a denial-of-service.

CVE-2022-20494
Android General
5.5
MEDIUM
EPSS
1.8%
2022 1 PoC

In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-243794204

CVE-2022-3114
Kernel General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-476 1 PoC

An issue was discovered in the Linux kernel through 5.16-rc6. imx_register_uart_clocks in drivers/clk/imx/clk.c lacks check of the return value of kcalloc() and will cause the null pointer dereference.

CVE-2022-45586
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2022 1 PoC

Stack overflow vulnerability in function Dict::find in xpdf/Dict.cc in xpdf 4.04, allows local attackers to cause a denial of service.

CVE-2022-34386
SupportAssist Client Consumer General
5.5
MEDIUM
EPSS
0.1%
2022 CWE-321 1 PoC

Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information.