5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-41024
QUARTZ-GOLD Networking
7.2
HIGH
EPSS
3.5%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'no vpn pptp advanced name WORD dns (yes|no) mtu <128-16384> mru <128-16384> mppe (on|off) stateful (on|off)' command template.

CVE-2022-41022
QUARTZ-GOLD Networking
7.2
HIGH
EPSS
3.5%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'no vpn l2tp advanced name WORD dns (yes|no) mtu <128-16384> mru <128-16384> auth (on|off) password (WORD|null) options WORD' command template.

CVE-2022-41013
QUARTZ-GOLD General
7.2
HIGH
EPSS
3.5%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'static dhcp mac WORD (WORD|null) ip A.B.C.D hostname (WORD|null) description (WORD|null)' command template.

CVE-2022-0587
librenms/librenms General
7.1
HIGH
EPSS
0.0%
2022 CWE-285 1 PoC

Improper Authorization in Packagist librenms/librenms prior to 22.2.0.

CVE-2022-4504
openemr/openemr General
7.1
HIGH
EPSS
0.4%
2022 CWE-20 1 PoC

Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.0.2.

CVE-2022-23400
ImageGear General
7.1
HIGH
EPSS
0.3%
2022 CWE-193 1 PoC

A stack-based buffer overflow vulnerability exists in the IGXMPXMLParser::parseDelimiter functionality of Accusoft ImageGear 19.10. A specially-crafted PSD file can overflow a stack buffer, which could either lead to denial of service or, depending on the application, to an information leak. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-2066
neorazorx/facturascripts Web
7.1
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository neorazorx/facturascripts prior to 2022.06.

CVE-2022-0370
livehelperchat/livehelperchat Web
7.1
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.

CVE-2022-39909
Samsung Gear IconX PC Manager General
7.1
HIGH
EPSS
0.0%
2022 CWE-345 1 PoC

Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.221019.51 allows local attackers to create arbitrary file using symbolic link.

CVE-2022-0896
microweber/microweber General
7.1
HIGH
EPSS
1.0%
2022 CWE-1336 1 PoC

Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-50799
Fetch Softworks Fetch FTP Client General
7.1
HIGH
EPSS
0.1%
2022 CWE-770 2 PoCs

Fetch FTP Client 5.8.2 contains a denial of service vulnerability that allows attackers to trigger 100% CPU consumption by sending long server responses. Attackers can send specially crafted FTP server responses exceeding 2K bytes to cause excessive resource utilization and potentially crash the application.

CVE-2022-4692
usememos/memos Web
7.1
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.

CVE-2022-31647
Software Genérico DevOps Web Windows
7.1
HIGH
EPSS
0.0%
2022 1 PoC

Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFolder parameter, a different vulnerability than CVE-2022-26659.

CVE-2022-1452
radareorg/radare2 Web
7.1
HIGH
EPSS
0.3%
2022 CWE-125 2 PoCs

Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash. More details see [CWE-125: Out-of-bounds read](https://cwe.mitre.org/data/definitions/125.html).

CVE-2022-4690
usememos/memos Web
7.1
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.

CVE-2022-50894
VIAVIWEB Wallpaper Admin Web Database
7.1
HIGH
EPSS
0.0%
2022 CWE-89 1 PoC

VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the img_id parameter. Attackers can send GET requests to edit_gallery_image.php with malicious img_id values to extract database information.

CVE-2022-0436
gruntjs/grunt General
7.1
HIGH
EPSS
0.1%
2022 CWE-22 1 PoC

Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.

CVE-2022-2989
podman DevOps
7.1
HIGH
EPSS
0.0%
2022 CWE-842 1 PoC

An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.

CVE-2022-29458
Software Genérico General
7.1
HIGH
EPSS
0.0%
2022 3 PoCs

ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.

CVE-2022-1400
CMDB Web
7.1
HIGH
EPSS
0.4%
2022 CWE-321 1 PoC

Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, allows an attacker to leak session IDs and elevate privileges. This issue affects: Device42 CMDB versions prior to 18.01.00.