5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0631
mruby/mruby General
5.9
MEDIUM
EPSS
0.3%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.

CVE-2022-22787
Zoom Client for Meetings for Android Windows
5.9
MEDIUM
EPSS
0.3%
2022 1 PoC

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.10.0 fails to properly validate the hostname during a server switch request. This issue could be used in a more sophisticated attack to trick an unsuspecting users client to connect to a malicious server when attempting to use Zoom services.

CVE-2022-0712
radareorg/radare2 General
5.9
MEDIUM
EPSS
0.4%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4.

CVE-2022-25897
org.eclipse.milo:sdk-server General
5.9
MEDIUM
EPSS
0.3%
2022 1 PoC

The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

CVE-2022-22464
Security Verify Access General
5.9
MEDIUM
EPSS
0.1%
2022 1 PoC

IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 225081.

CVE-2022-42966
cleo General
5.9
MEDIUM
EPSS
0.3%
2022 CWE-1333 1 PoC

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the cleo PyPI package, when an attacker is able to supply arbitrary input to the Table.set_rows method

CVE-2022-27567
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

Null pointer dereference vulnerability in parser_hvcC function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attackers.

CVE-2022-3035
snipe/snipe-it Web
5.9
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11.

CVE-2022-22405
Aspera Faspex Web
5.9
MEDIUM
EPSS
0.0%
2022 CWE-311 1 PoC

IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 222576.

CVE-2022-43603
OpenImageIO General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-476 1 PoC

A denial of service vulnerability exists in the ZfileOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-24404
TETRA Standard General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-353 1 PoC

Lack of cryptographic integrity check on TETRA air-interface encrypted traffic. Since a stream cipher is employed, this allows an active adversary to manipulate cleartext data in a bit-by-bit fashion.

CVE-2022-2596
node-fetch/node-fetch General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-1333 1 PoC

Inefficient Regular Expression Complexity in GitHub repository node-fetch/node-fetch prior to 3.2.10.

CVE-2022-1286
mruby/mruby General
5.9
MEDIUM
EPSS
0.6%
2022 CWE-122 1 PoC

heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

CVE-2022-22401
Aspera Faspex General
5.9
MEDIUM
EPSS
0.0%
2022 1 PoC

IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather or persuade a naive user to supply sensitive information. IBM X-Force ID: 222567.

CVE-2022-43592
OpenImageIO General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-125 1 PoC

An information disclosure vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability.

CVE-2022-42964
pymatgen General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-1333 1 PoC

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the pymatgen PyPI package, when an attacker is able to supply arbitrary input to the GaussianInput.from_string method

CVE-2022-1930
eth-account General
5.9
MEDIUM
EPSS
0.3%
2022 CWE-1333 1 PoC

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the eth-account PyPI package, when an attacker is able to supply arbitrary input to the encode_structured_data method

CVE-2022-23130
GENESIS64 Cloud
5.9
MEDIUM
EPSS
0.1%
2022 CWE-126 1 PoC

Buffer Over-read vulnerability in Mitsubishi Electric MC Works64 versions 4.00A to 4.04E, Mitsubishi Electric GENESIS64 versions 10.97 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 and prior, Mitsubishi Electric ICONICS Suite versions 10.97 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97 and prior, Mitsubishi Electric GENESIS32 versions 9.7 and prior, and Mitsubishi Electric Iconics Digital Solutions GENESIS32 versions 9.7 and prior allows an attacker to cause a DoS condition in the database server by getting a legitimat

CVE-2022-30735
Samsung Account General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_token without permission.

CVE-2022-24928
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-815 1 PoC

Security misconfiguration of RKP in kernel prior to SMR Mar-2022 Release 1 allows a system not to be protected by RKP.