2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-41199
SAP 3D Visual Enterprise Viewer General
7.8
HIGH
EPSS
1.8%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated Open Inventor File (.iv, vrml.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVE-2022-1897
vim/vim General
7.8
HIGH
EPSS
0.5%
2022 CWE-787 2 PoCs

Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.

CVE-2022-3520
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.

CVE-2022-3328
snapd General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

Race condition in snap-confine's must_mkdir_and_open_with_perms()

CVE-2022-24369
PDF Reader General
7.8
HIGH
EPSS
0.7%
2022 CWE-787 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 images. Crafted data in a JP2 image can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16087.

CVE-2022-24362
PDF Reader General
7.8
HIGH
EPSS
0.7%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15987.

CVE-2022-43310
Software Genérico General
7.8
HIGH
EPSS
0.0%
2022 1 PoC

An Uncontrolled Search Path Element in Foxit Software released Foxit Reader v11.2.118.51569 allows attackers to escalate privileges when searching for DLL libraries without specifying an absolute path.

CVE-2022-30166
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
7.6%
2022 1 PoC

Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

CVE-2022-2581
vim/vim General
7.8
HIGH
EPSS
0.0%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0104.

CVE-2022-42847
macOS General
7.8
HIGH
EPSS
0.2%
2022 1 PoC

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.1. An app may be able to execute arbitrary code with kernel privileges.

CVE-2022-23947
KiCad General
7.8
HIGH
EPSS
0.8%
2022 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-28676
PDF Reader General
7.8
HIGH
EPSS
0.4%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16643.

CVE-2022-20492
Android General
7.8
HIGH
EPSS
0.0%
2022 1 PoC

In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242704043

CVE-2022-32911
iOS General
7.8
HIGH
EPSS
0.2%
2022 2 PoCs

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to execute arbitrary code with kernel privileges.

CVE-2022-24971
PDF Reader General
7.8
HIGH
EPSS
1.0%
2022 CWE-125 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPEG2000 images. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15812.

CVE-2022-22031
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.3%
2022 1 PoC

Windows Credential Guard Domain-joined Public Key Elevation of Privilege Vulnerability

CVE-2022-2650
wger-project/wger General
7.8
HIGH
EPSS
0.2%
2022 CWE-307 3 PoCs

Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2.

CVE-2022-2522
vim/vim General
7.8
HIGH
EPSS
0.0%
2022 CWE-122 2 PoCs

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0061.

CVE-2022-46623
Software Genérico Database
7.8
HIGH
EPSS
0.3%
2022 1 PoC

Judging Management System v1.0.0 was discovered to contain a SQL injection vulnerability via the username parameter.

CVE-2022-3155
Thunderbird General
7.8
HIGH
EPSS
0.0%
2022 1 PoC

When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was started immediately without asking the user to confirm. This vulnerability affects Thunderbird < 102.3.