3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-35093
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

SWFTools commit 772e55a2 was discovered to contain a global buffer overflow via DCTStream::transformDataUnit at /xpdf/Stream.cc.

CVE-2022-0909
libtiff General
5.5
MEDIUM
EPSS
0.2%
2022 1 PoC

Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f8d0f9aa.

CVE-2022-45586
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2022 1 PoC

Stack overflow vulnerability in function Dict::find in xpdf/Dict.cc in xpdf 4.04, allows local attackers to cause a denial of service.

CVE-2022-20494
Android General
5.5
MEDIUM
EPSS
1.8%
2022 1 PoC

In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-243794204

CVE-2022-0596
microweber/microweber General
5.4
MEDIUM
EPSS
0.3%
2022 CWE-1284 1 PoC

Improper Validation of Specified Quantity in Input in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-48085
Software Genérico General
5.4
MEDIUM
EPSS
0.3%
2022 2 PoCs

Softr v2.0 was discovered to contain a HTML injection vulnerability via the Work Space Name parameter.

CVE-2022-4235
RushBet General
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

RushBet version 2022.23.1-b490616d allows a remote attacker to steal customer accounts via use of a malicious application. This is possible because the application exposes an activity and does not properly validate the data it receives.

CVE-2022-0756
salesagility/suitecrm General
5.4
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

CVE-2022-41542
Software Genérico General
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

devhub 0.102.0 was discovered to contain a broken session control.

CVE-2022-28286
Thunderbird General
5.4
MEDIUM
EPSS
0.2%
2022 1 PoC

Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

CVE-2022-26088
Software Genérico General
5.4
MEDIUM
EPSS
0.4%
2022 3 PoCs

An issue was discovered in BMC Remedy before 22.1. Email-based Incident Forwarding allows remote authenticated users to inject HTML (such as an SSRF payload) into the Activity Log by placing it in the To: field. This affects rendering that occurs upon a click in the "number of recipients" field. NOTE: the vendor's position is that "no real impact is demonstrated."

CVE-2022-33927
Wyse Management Suite General
5.4
MEDIUM
EPSS
0.4%
2022 CWE-384 1 PoC

Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could exploit this by taking advantage of a user with multiple active sessions in order to hijack a user's session.

CVE-2022-22331
SterlingPartner Engagement Manager General
5.4
MEDIUM
EPSS
0.1%
2022 1 PoC

IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 219130.

CVE-2022-41208
SAP Financial Consolidation General
5.4
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with user privileges to alter current user session. On successful exploitation, the attacker can view or modify information, causing a limited impact on confidentiality and integrity of the application.

CVE-2022-0727
chocobozzz/peertube General
5.4
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.

CVE-2022-1850
filegator/filegator General
5.4
MEDIUM
EPSS
0.4%
2022 CWE-22 1 PoC

Path Traversal in GitHub repository filegator/filegator prior to 7.8.0.

CVE-2022-41206
SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) General
5.4
MEDIUM
EPSS
0.4%
2022 CWE-79 1 PoC

SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows an authenticated attacker to send user-controlled inputs when OLAP connections are created and edited in the Central Management Console. On successful exploitation, there could be a limited impact on confidentiality and integrity of the application.

CVE-2022-0829
webmin/webmin General
5.4
MEDIUM
EPSS
0.4%
2022 CWE-285 2 PoCs

Improper Authorization in GitHub repository webmin/webmin prior to 1.990.

CVE-2022-3326
ikus060/rdiffweb General
5.4
MEDIUM
EPSS
0.2%
2022 CWE-521 1 PoC

Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.9.

CVE-2022-0726
chocobozzz/peertube General
5.4
MEDIUM
EPSS
0.2%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.