5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-39836
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 2 PoCs

An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There is a heap-based buffer over-read of one byte.

CVE-2022-35099
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

SWFTools commit 772e55a2 was discovered to contain a stack overflow via ImageStream::getPixel(unsigned char*) at /xpdf/Stream.cc.

CVE-2022-40363
Software Genérico General
5.5
MEDIUM
EPSS
0.2%
2022 1 PoC

A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cause a Denial of Service (DoS) via a crafted NFC file.

CVE-2022-39844
Smart Switch PC General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-354 1 PoC

Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.22083 allows local attackers to delete arbitrary directory using directory junction.

CVE-2022-36442
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2022 1 PoC

An issue was discovered in Zebra Enterprise Home Screen 4.1.19. By using the embedded Google Chrome application, it is possible to install an unauthorized application via a downloaded APK.

CVE-2022-3113
Kernel General
5.5
MEDIUM
EPSS
3.4%
2022 CWE-476 1 PoC

An issue was discovered in the Linux kernel through 5.16-rc6. mtk_vcodec_fw_vpu_init in drivers/media/platform/mtk-vcodec/mtk_vcodec_fw_vpu.c lacks check of the return value of devm_kzalloc() and will cause the null pointer dereference.

CVE-2022-46351
SCALANCE X204RNA (HSR) General
5.5
MEDIUM
EPSS
0.1%
2022 CWE-400 1 PoC

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). Specially crafted PROFINET DCP packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2).

CVE-2022-3597
libtiff General
5.5
MEDIUM
EPSS
0.0%
2022 1 PoC

LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6826, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191.

CVE-2022-34385
SupportAssist Client Consumer General
5.5
MEDIUM
EPSS
0.1%
2022 CWE-326 1 PoC

SupportAssist for Home PCs (version 3.11.4 and prior) and  SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information.

CVE-2022-23173
Priority web General
5.5
MEDIUM
EPSS
0.2%
2022 1 PoC

this vulnerability affect user that even not allowed to access via the web interface. First of all, the attacker needs to access the "Login menu - demo site" then he can see in this menu all the functionality of the application. If the attacker will try to click on one of the links, he will get an answer that he is not authorized because he needs to log in with credentials. after he performed log in to the system there are some functionalities that the specific user is not allowed to perform because he was configured with low privileges however all the attacker need to do in order to achieve h

CVE-2022-34681
vGPU software (guest driver) - Windows, NVIDIA Cloud Gaming (guest driver) Cloud Windows
5.5
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler, where improper input validation of a display-related data structure may lead to denial of service.

CVE-2022-1068
Modbus Slave General
5.5
MEDIUM
EPSS
0.2%
2022 CWE-121 1 PoC

Modbus Tools Modbus Slave (versions 7.4.2 and prior) is vulnerable to a stack-based buffer overflow in the registration field. This may cause the program to crash when a long character string is used.

CVE-2022-21877
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
15.0%
2022 1 PoC

Storage Spaces Controller Information Disclosure Vulnerability

CVE-2022-39401
Solaris Operating System Database
5.5
MEDIUM
EPSS
0.0%
2022 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2022-1771
vim/vim General
5.5
MEDIUM
EPSS
0.1%
2022 CWE-674 1 PoC

Uncontrolled Recursion in GitHub repository vim/vim prior to 8.2.4975.

CVE-2022-3626
libtiff General
5.5
MEDIUM
EPSS
0.0%
2022 1 PoC

LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c:340 when called from processCropSelections, tools/tiffcrop.c:7619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191.

CVE-2022-0762
microweber/microweber General
5.5
MEDIUM
EPSS
0.2%
2022 CWE-863 1 PoC

Incorrect Authorization in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-25814
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-276 1 PoC

PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.

CVE-2022-4415
systemd General
5.5
MEDIUM
EPSS
0.0%
2022 CWE-200 2 PoCs

A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.

CVE-2022-3106
Kernel General
5.5
MEDIUM
EPSS
0.1%
2022 CWE-476 1 PoC

An issue was discovered in the Linux kernel through 5.16-rc6. ef100_update_stats in drivers/net/ethernet/sfc/ef100_nic.c lacks check of the return value of kmalloc().