7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0696
vim/vim General
6.2
MEDIUM
EPSS
0.2%
2022 CWE-476 2 PoCs

NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.

CVE-2022-42284
NVIDIA DGX servers General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-312 1 PoC

NVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credentials exposure.

CVE-2022-33732
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unprotected binder call.

CVE-2022-39164
AIX General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-400 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 235181.

CVE-2022-30744
Samsung Kies General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arbitrary code.

CVE-2022-33714
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1 allows attacker to reset a setting value related to mobile hotspot.

CVE-2022-39912
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-280 1 PoC

Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder.

CVE-2022-39165
AIX General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-400 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in CAA to cause a denial of service. IBM X-Force ID: 235183.

CVE-2022-40233
AIX General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX TCP/IP kernel extension to cause a denial of service. IBM X-Force ID: 235599.

CVE-2022-39890
Samsung Billing General
6.2
MEDIUM
EPSS
0.2%
2022 CWE-285 1 PoC

Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information.

CVE-2022-28783
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages without permission. The patch adds proper validation logic for removing package name.

CVE-2022-0240
mruby/mruby General
6.2
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

mruby is vulnerable to NULL Pointer Dereference

CVE-2022-43589
CBFS Filter General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-476 1 PoC

A null pointer dereference vulnerability exists in the handle_ioctl_8314C functionality of Callback technologies CBFS Filter 20.0.8317. A specially crafted I/O request packet (IRP) can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability.

CVE-2022-28791
Galaxy Store General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a specific path. The patch adds proper protection to prevent overwrite to existing files.

CVE-2022-20360
Android General
6.2
MEDIUM
EPSS
0.0%
2022 2 PoCs

In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228314987

CVE-2022-28789
Voice Note General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

Unprotected activities in Voice Note prior to version 21.3.51.11 allows attackers to record voice without user interaction. The patch adds proper permission for vulnerable activities.

CVE-2022-43485
OneWireless General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-330 1 PoC

Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1

CVE-2022-33718
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-863 1 PoC

An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data.

CVE-2022-21385
Oracle Linux Database
6.2
MEDIUM
EPSS
0.1%
2022 1 PoC

A flaw in net_rds_alloc_sgs() in Oracle Linux kernels allows unprivileged local users to crash the machine. CVSS 3.1 Base Score 6.2 (Availability impacts). CVSS Vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVE-2022-25825
Samsung Account General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-287 1 PoC

Improper access control vulnerability in Samsung Account prior to version 13.1.0.1 allows attackers to access to the authcode for sign-in.