2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-37384
PDF Reader General
7.8
HIGH
EPSS
2.0%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the delay method. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17327.

CVE-2022-42176
Software Genérico General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

In PCTechSoft PCSecure V5.0.8.xw, use of Hard-coded Credentials in configuration files leads to admin panel access.

CVE-2022-24360
PDF Reader General
7.8
HIGH
EPSS
0.7%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15744.

CVE-2022-3569
Zimbra Collaboration Suite (ZCS) General
7.8
HIGH
EPSS
2.8%
2022 CWE-271 1 PoC

Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectively coerce postfix into running arbitrary commands as 'root'.

CVE-2022-42840
macOS General
7.8
HIGH
EPSS
0.3%
2022 5 PoCs

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary code with kernel privileges.

CVE-2022-42261
vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
7.8
HIGH
EPSS
0.1%
2022 CWE-120 1 PoC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may cause data tampering, information disclosure, or denial of service.

CVE-2022-33896
Hancom Office 2020 General
7.8
HIGH
EPSS
0.2%
2022 CWE-124 2 PoCs

A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files. A specially-crafted malformed file can cause memory corruption by using memory before buffer start, which can lead to code execution. A victim would need to access a malicious file to trigger this vulnerability.

CVE-2022-21974
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
8.8%
2022 1 PoC

Roaming Security Rights Management Services Remote Code Execution Vulnerability

CVE-2022-28673
PDF Reader General
7.8
HIGH
EPSS
0.4%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16641.

CVE-2022-37388
PDF Reader General
7.8
HIGH
EPSS
2.0%
2022 CWE-125 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.2.53575. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17516.

CVE-2022-42053
Software Genérico Networking
7.8
HIGH
EPSS
1.4%
2022 1 PoC

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer parameter in the setPortMapping function.

CVE-2022-42260
vGPU software (guest driver) - Linux, NVIDIA Cloud Gaming (guest driver) Cloud
7.8
HIGH
EPSS
0.2%
2022 CWE-281 1 PoC

NVIDIA vGPU Display Driver for Linux guest contains a vulnerability in a D-Bus configuration file, where an unauthorized user in the guest VM can impact protected D-Bus endpoints, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

CVE-2022-24908
PDF Reader General
7.8
HIGH
EPSS
2.1%
2022 CWE-125 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 images. Crafted data in a JP2 image can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16187.

CVE-2022-28638
HPE Integrated Lights-Out 5 (iLO 5) General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

An isolated local disclosure of information and potential isolated local arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses these security vulnerabilities.

CVE-2022-38038
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.9%
2022 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2022-23946
KiCad General
7.8
HIGH
EPSS
0.5%
2022 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-3352
vim/vim General
7.8
HIGH
EPSS
0.0%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0614.

CVE-2022-1898
vim/vim General
7.8
HIGH
EPSS
0.3%
2022 CWE-416 2 PoCs

Use After Free in GitHub repository vim/vim prior to 8.2.

CVE-2022-28674
PDF Reader General
7.8
HIGH
EPSS
0.4%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16644.

CVE-2022-49168
Linux General
7.8
HIGH
EPSS
0.0%
2022 1 PoC

In the Linux kernel, the following vulnerability has been resolved: btrfs: do not clean up repair bio if submit fails The submit helper will always run bio_endio() on the bio if it fails to submit, so cleaning up the bio just leads to a variety of use-after-free and NULL pointer dereference bugs because we race with the endio function that is cleaning up the bio. Instead just return BLK_STS_OK as the repair function has to continue to process the rest of the pages, and the endio for the repair bio will do the appropriate cleanup for the page that it was given.