5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2522
vim/vim General
7.8
HIGH
EPSS
0.0%
2022 CWE-122 2 PoCs

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0061.

CVE-2022-22031
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.3%
2022 1 PoC

Windows Credential Guard Domain-joined Public Key Elevation of Privilege Vulnerability

CVE-2022-43310
Software Genérico General
7.8
HIGH
EPSS
0.0%
2022 1 PoC

An Uncontrolled Search Path Element in Foxit Software released Foxit Reader v11.2.118.51569 allows attackers to escalate privileges when searching for DLL libraries without specifying an absolute path.

CVE-2022-2947
HyperView Player General
7.8
HIGH
EPSS
0.1%
2022 CWE-119 1 PoC

Altair HyperView Player versions 2021.1.0.27 and prior perform operations on a memory buffer but can read from or write to a memory location outside of the intended boundary of the buffer. This hits initially as a read access violation, leading to a memory corruption situation.

CVE-2022-2264
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.

CVE-2022-37988
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
1.2%
2022 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2022-23947
KiCad General
7.8
HIGH
EPSS
0.8%
2022 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-34670
vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
7.8
HIGH
EPSS
0.1%
2022 CWE-197 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause truncation errors when casting a primitive to a primitive of smaller size causes data to be lost in the conversion, which may lead to denial of service or information disclosure.

CVE-2022-33888
utodesk® AutoCAD®, Advance Steel and Civil 3D® General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

A malicious crafted Dwg2Spd file when processed through Autodesk DWG application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

CVE-2022-43484
TERASOLUNA Global Framework and TERASOLUNA Server Framework for Java (Rich) Web
7.8
HIGH
EPSS
0.1%
2022 2 PoCs

TERASOLUNA Global Framework 1.0.0 (Public review version) and TERASOLUNA Server Framework for Java (Rich) 2.0.0.2 to 2.0.5.1 are vulnerable to a ClassLoader manipulation vulnerability due to using the old version of Spring Framework which contains the vulnerability.The vulnerability is caused by an improper input validation issue in the binding mechanism of Spring MVC. By the application processing a specially crafted file, arbitrary code may be executed with the privileges of the application.

CVE-2022-1927
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-126 2 PoCs

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

CVE-2022-42176
Software Genérico General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

In PCTechSoft PCSecure V5.0.8.xw, use of Hard-coded Credentials in configuration files leads to admin panel access.

CVE-2022-3699
HardwareScanPlugin General
7.8
HIGH
EPSS
85.1%
2022 CWE-787 2 PoCs

A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45 that could allow a local user to execute code with elevated privileges.

CVE-2022-45934
Software Genérico General
7.8
HIGH
EPSS
0.4%
2022 4 PoCs

An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets.

CVE-2022-3569
Zimbra Collaboration Suite (ZCS) General
7.8
HIGH
EPSS
2.8%
2022 CWE-271 1 PoC

Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectively coerce postfix into running arbitrary commands as 'root'.

CVE-2022-28307
View General
7.8
HIGH
EPSS
1.5%
2022 CWE-125 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.16.02.022. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF files. Crafted data in a DXF file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16306.

CVE-2022-42840
macOS General
7.8
HIGH
EPSS
0.3%
2022 5 PoCs

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary code with kernel privileges.

CVE-2022-30168
Microsoft Photos General
7.8
HIGH
EPSS
2.5%
2022 1 PoC

Microsoft Photos App Remote Code Execution Vulnerability

CVE-2022-42849
tvOS Web
7.8
HIGH
EPSS
0.1%
2022 3 PoCs

An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2, watchOS 9.2. A user may be able to elevate privileges.

CVE-2022-33896
Hancom Office 2020 General
7.8
HIGH
EPSS
0.2%
2022 CWE-124 2 PoCs

A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files. A specially-crafted malformed file can cause memory corruption by using memory before buffer start, which can lead to code execution. A victim would need to access a malicious file to trigger this vulnerability.