7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-22405
Aspera Faspex Web
5.9
MEDIUM
EPSS
0.0%
2022 CWE-311 1 PoC

IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 222576.

CVE-2022-36839
Samsung Checkout Database
5.9
MEDIUM
EPSS
0.2%
2022 CWE-89 1 PoC

SQL injection vulnerability via IAPService in Samsung Checkout prior to version 5.0.53.1 allows attackers to access IAP information.

CVE-2022-36861
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-269 1 PoC

Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI privilege.

CVE-2022-26095
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.4%
2022 CWE-476 1 PoC

Null pointer dereference vulnerability in parser_colr function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

CVE-2022-43596
OpenImageIO General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-125 1 PoC

An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability.

CVE-2022-36874
Waterplugin General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-280 1 PoC

Improper Handling of Insufficient Permissions or Privileges vulnerability in Waterplugin prior to 2.2.11.22040751 allows attacker to access device IMEI and Serial number.

CVE-2022-21581
Banking Trade Finance Web Database
5.9
MEDIUM
EPSS
0.3%
2022 1 PoC

Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance accessible data as well as unauthoriz

CVE-2022-21475
Banking Payments Web Database
5.9
MEDIUM
EPSS
0.4%
2022 1 PoC

Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Payments accessible data as well as unauthorized read access

CVE-2022-4304
OpenSSL General
5.9
MEDIUM
EPSS
0.2%
2022 1 PoC

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server cou

CVE-2022-4644
ikus060/rdiffweb General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-601 1 PoC

Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.4.

CVE-2022-43603
OpenImageIO General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-476 1 PoC

A denial of service vulnerability exists in the ZfileOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-28541
Samsung Update General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-22 1 PoC

Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Update permission.

CVE-2022-39885
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-280 1 PoC

Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR Nov-2022 Release 1 allows local attacker to access to Device information.

CVE-2022-24404
TETRA Standard General
5.9
MEDIUM
EPSS
0.1%
2022 CWE-353 1 PoC

Lack of cryptographic integrity check on TETRA air-interface encrypted traffic. Since a stream cipher is employed, this allows an active adversary to manipulate cleartext data in a bit-by-bit fashion.

CVE-2022-2596
node-fetch/node-fetch General
5.9
MEDIUM
EPSS
0.2%
2022 CWE-1333 1 PoC

Inefficient Regular Expression Complexity in GitHub repository node-fetch/node-fetch prior to 3.2.10.

CVE-2022-39879
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2022 CWE-285 1 PoC

Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.

CVE-2022-25871
querymen Web
5.9
MEDIUM
EPSS
0.3%
2022 2 PoCs

All versions of package querymen are vulnerable to Prototype Pollution if the parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. Note: This vulnerability derives from an incomplete fix of [CVE-2020-7600](https://security.snyk.io/vuln/SNYK-JS-QUERYMEN-559867).

CVE-2022-1286
mruby/mruby General
5.9
MEDIUM
EPSS
0.6%
2022 CWE-122 1 PoC

heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

CVE-2022-22401
Aspera Faspex General
5.9
MEDIUM
EPSS
0.0%
2022 1 PoC

IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather or persuade a naive user to supply sensitive information. IBM X-Force ID: 222567.

CVE-2022-40897
Software Genérico General
5.9
MEDIUM
EPSS
0.5%
2022 1 PoC

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.