5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2571
vim/vim General
7.8
HIGH
EPSS
0.0%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0101.

CVE-2022-2284
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.

CVE-2022-20495
Android General
7.8
HIGH
EPSS
0.0%
2022 1 PoC

In getEnabledAccessibilityServiceList of AccessibilityManager.java, there is a possible way to hide an accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-243849844

CVE-2022-20493
Android General
7.8
HIGH
EPSS
0.0%
2022 1 PoC

In Condition of Condition.java, there is a possible way to grant notification access due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242846316

CVE-2022-44725
Software Genérico General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. This allows a normal user to create a malicious file that is loaded by LDS (running as a high-privilege user).

CVE-2022-29581
Kernel General
7.8
HIGH
EPSS
0.2%
2022 CWE-911 7 PoCs

Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions.

CVE-2022-41303
FBX SDK General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in Autodesk FBX SDK 2020 version causing the application to reference a memory location controlled by an unauthorized third party, thereby running arbitrary code on the system.

CVE-2022-42720
Software Genérico General
7.8
HIGH
EPSS
0.6%
2022 2 PoCs

Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger use-after-free conditions to potentially execute code.

CVE-2022-41992
PowerISO General
7.8
HIGH
EPSS
0.1%
2022 CWE-787 1 PoC

A memory corruption vulnerability exists in the VHD File Format parsing CXSPARSE record functionality of PowerISO PowerISO 8.3. A specially-crafted file can lead to an out-of-bounds write. A victim needs to open a malicious file to trigger this vulnerability.

CVE-2022-2946
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0246.

CVE-2022-3605
WP CSV Exporter Web Windows
7.8
HIGH
EPSS
0.3%
2022 1 PoC

The WP CSV Exporter WordPress plugin before 1.3.7 does not properly escape the fields when exporting data as CSV, leading to a CSV injection vulnerability.

CVE-2022-2285
vim/vim General
7.8
HIGH
EPSS
0.2%
2022 CWE-190 1 PoC

Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.

CVE-2022-38774
Elastic Endpoint Security and Elastic Endgame Security Windows
7.8
HIGH
EPSS
0.1%
2022 CWE-269 1 PoC

An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account.

CVE-2022-3297
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0579.

CVE-2022-36443
Software Genérico General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The device allows the administrator to lock some communication channels (wireless and SD card) but it is still possible to use a physical connection (Ethernet cable) without restriction.

CVE-2022-20818
Cisco SD-WAN Solution Networking
7.8
HIGH
EPSS
0.5%
2022 CWE-25 1 PoC

Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these vulnerabilities by running a malicious command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.

CVE-2022-32942
macOS General
7.8
HIGH
EPSS
0.3%
2022 3 PoCs

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2. An app may be able to execute arbitrary code with kernel privileges.

CVE-2022-36122
Software Genérico General
7.8
HIGH
EPSS
0.0%
2022 1 PoC

The Automox Agent before 40 on Windows incorrectly sets permissions on key files.

CVE-2022-2345
vim/vim General
7.8
HIGH
EPSS
0.0%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0046.

CVE-2022-24358
PDF Reader Web
7.8
HIGH
EPSS
0.7%
2022 CWE-125 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15703.