5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0240
mruby/mruby General
6.2
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

mruby is vulnerable to NULL Pointer Dereference

CVE-2022-43589
CBFS Filter General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-476 1 PoC

A null pointer dereference vulnerability exists in the handle_ioctl_8314C functionality of Callback technologies CBFS Filter 20.0.8317. A specially crafted I/O request packet (IRP) can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability.

CVE-2022-36831
Samsung notes General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-22 1 PoC

Path traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows attacker to access some file as Samsung Notes permission.

CVE-2022-36830
Charm by Samsung General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-927 1 PoC

PendingIntent hijacking vulnerability in cancelAlarmManager in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.

CVE-2022-20360
Android General
6.2
MEDIUM
EPSS
0.0%
2022 2 PoCs

In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228314987

CVE-2022-2417
GitLab DevOps
6.2
MEDIUM
EPSS
0.1%
2022 1 PoC

Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could be abused in supply chain attacks where a victim pinned to a specific Git commit of the project.

CVE-2022-33702
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-285 1 PoC

Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass Knoxguard lock by factory reset.

CVE-2022-43590
CBFS Filter General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-476 1 PoC

A null pointer dereference vulnerability exists in the handle_ioctl_0x830a0_systembuffer functionality of Callback technologies CBFS Filter 20.0.8317. A specially crafted I/O request packet (IRP) can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability.

CVE-2022-43848
AIX General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service. IBM X-Force ID: 239169.

CVE-2022-25664
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables General
6.2
MEDIUM
EPSS
0.2%
2022 1 PoC

Information disclosure due to exposure of information while GPU reads the data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

CVE-2022-33689
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unprotected binder call.

CVE-2022-39165
AIX General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-400 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-Force ID: 235183.

CVE-2022-28789
Voice Note General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

Unprotected activities in Voice Note prior to version 21.3.51.11 allows attackers to record voice without user interaction. The patch adds proper permission for vulnerable activities.

CVE-2022-28792
Gear IconX PC Manager General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-427 1 PoC

DLL hijacking vulnerability in Gear IconX PC Manager prior to version 2.1.220405.51 allows attacker to execute arbitrary code. The patch adds proper absolute path to prevent dll hijacking.

CVE-2022-43588
CBFS Filter General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-476 1 PoC

A null pointer dereference vulnerability exists in the handle_ioctl_83150 functionality of Callback technologies CBFS Filter 20.0.8317. A specially crafted I/O request packet (IRP) can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability.

CVE-2022-30722
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-285 1 PoC

Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Account.

CVE-2022-27843
Kies General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

DLL hijacking vulnerability in Kies prior to version 2.6.4.22014_2 allows attacker to execute abitrary code.

CVE-2022-39186
BV-10 Performance Endpoint Unit General
6.2
MEDIUM
EPSS
0.0%
2022 1 PoC

EXFO - BV-10 Performance Endpoint Unit misconfiguration. System configuration file has misconfigured permissions

CVE-2022-30744
Samsung Kies General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arbitrary code.

CVE-2022-43485
OneWireless General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-330 1 PoC

Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1