2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-24356
PDF Reader General
7.8
HIGH
EPSS
0.7%
2022 CWE-125 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader Foxit reader 11.0.1.0719 macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the OnMouseExit method. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14848.

CVE-2022-1927
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-126 2 PoCs

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

CVE-2022-2289
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.

CVE-2022-43664
Ichitaro General
7.8
HIGH
EPSS
0.4%
2022 CWE-416 2 PoCs

A use-after-free vulnerability exists within the way Ichitaro Word Processor 2022, version 1.0.1.57600, processes protected documents. A specially crafted document can trigger reuse of freed memory, which can lead to further memory corruption and potentially result in arbitrary code execution. An attacker can provide a malicious document to trigger this vulnerability.

CVE-2022-22996
G-RAID 4/8 Software Utility Windows
7.8
HIGH
EPSS
0.1%
2022 CWE-427 1 PoC

The G-RAID 4/8 Software Utility setups for Windows were affected by a DLL hijacking vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the system user.

CVE-2022-2951
HyperView Player General
7.8
HIGH
EPSS
0.2%
2022 CWE-129 1 PoC

Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to improper validation of array index vulnerability during processing of H3D files. A DWORD value from a PoC file is extracted and used as an index to write to a buffer, leading to memory corruption.

CVE-2022-3910
Linux Kernel Web Networking
7.8
HIGH
EPSS
0.6%
2022 CWE-416 2 PoCs

Use After Free vulnerability in Linux Kernel allows Privilege Escalation. An improper Update of Reference Count in io_uring leads to Use-After-Free and Local Privilege Escalation. When io_msg_ring was invoked with a fixed file, it called io_fput_file() which improperly decreased its reference count (leading to Use-After-Free and Local Privilege Escalation). Fixed files are permanently registered to the ring, and should not be put separately. We recommend upgrading past commit https://github.com/torvalds/linux/commit/fc7222c3a9f56271fba02aabbfbae999042f1679 https://github.com/torvalds/linux/c

CVE-2022-26061
libhdf5 Networking
7.8
HIGH
EPSS
0.1%
2022 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-4095
Kernel General
7.8
HIGH
EPSS
0.0%
2022 CWE-416 1 PoC

A use-after-free flaw was found in Linux kernel before 5.19.2. This issue occurs in cmd_hdl_filter in drivers/staging/rtl8712/rtl8712_cmd.c, allowing an attacker to launch a local denial of service attack and gain escalation of privileges.

CVE-2022-35259
Ivanti Endpoint Manager General
7.8
HIGH
EPSS
0.6%
2022 CWE-91 1 PoC

XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to run and possibly execute to gain unauthorized privileges.

CVE-2022-37956
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.8%
2022 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2022-21974
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
8.8%
2022 1 PoC

Roaming Security Rights Management Services Remote Code Execution Vulnerability

CVE-2022-42046
Software Genérico General
7.8
HIGH
EPSS
0.2%
2022 2 PoCs

wfshbr64.sys and wfshbr32.sys specially crafted IOCTL allows arbitrary user to perform local privilege escalation

CVE-2022-32168
notepad-plus-plus General
7.8
HIGH
EPSS
0.1%
2022 CWE-427 1 PoC

Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

CVE-2022-2947
HyperView Player General
7.8
HIGH
EPSS
0.1%
2022 CWE-119 1 PoC

Altair HyperView Player versions 2021.1.0.27 and prior perform operations on a memory buffer but can read from or write to a memory location outside of the intended boundary of the buffer. This hits initially as a read access violation, leading to a memory corruption situation.

CVE-2022-41307
Subassembly Composer General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

CVE-2022-24971
PDF Reader General
7.8
HIGH
EPSS
1.0%
2022 CWE-125 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPEG2000 images. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15812.

CVE-2022-30426
Software Genérico General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

There is a stack buffer overflow vulnerability, which could lead to arbitrary code execution in UEFI DXE driver on some Acer products. An attack could exploit this vulnerability to escalate privilege from ring 3 to ring 0, and hijack control flow during UEFI DXE execution. This affects Altos T110 F3 firmware version <= P13 (latest) and AP130 F2 firmware version <= P04 (latest) and Aspire 1600X firmware version <= P11.A3L (latest) and Aspire 1602M firmware version <= P11.A3L (latest) and Aspire 7600U firmware version <= P11.A4 (latest) and Aspire MC605 firmware version <= P11.A4L (latest) and A

CVE-2022-30190
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
93.6%
2022 75 PoCs

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.

CVE-2022-37969
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
11.6%
2022 3 PoCs

Windows Common Log File System Driver Elevation of Privilege Vulnerability