7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-45154
SUSE Linux Enterprise Server 12 General
4.4
MEDIUM
EPSS
0.0%
2022 CWE-312 1 PoC

A Cleartext Storage of Sensitive Information vulnerability in suppportutils of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 15 SP3 allows attackers that get access to the support logs to gain knowledge of the stored credentials This issue affects: SUSE Linux Enterprise Server 12 supportutils version 3.0.10-95.51.1CWE-312: Cleartext Storage of Sensitive Information and prior versions. SUSE Linux Enterprise Server 15 supportutils version 3.1.21-150000.5.44.1 and prior versions. SUSE Linux Enterprise Server 15 SP3 supportutils version 3.1.21-15030

CVE-2022-36841
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2022 CWE-122 1 PoC

A heap-based overflow vulnerability in PrepareRecogLibrary_Part function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

CVE-2022-25332
OMAP General
4.4
MEDIUM
EPSS
0.1%
2022 CWE-208 1 PoC

The AES implementation in the Texas Instruments OMAP L138 (secure variants), present in mask ROM, suffers from a timing side channel which can be exploited by an adversary with non-secure supervisor privileges by managing cache contents and collecting timing information for different ciphertext inputs. Using this side channel, the SK_LOAD secure kernel routine can be used to recover the Customer Encryption Key (CEK).

CVE-2022-22563
PowerScale OneFS General
4.4
MEDIUM
EPSS
0.0%
2022 CWE-223 1 PoC

Dell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A high-privileged user can exploit this vulnerability to not record information identifying the source of account information changes.

CVE-2022-28793
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2022 CWE-754 1 PoC

Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent change of Android ROT after first initialization at boot time.

CVE-2022-4843
radareorg/radare2 General
4.4
MEDIUM
EPSS
0.1%
2022 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.8.2.

CVE-2022-21512
PeopleSoft Enterprise PT PeopleTools Database
4.4
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Supported versions that are affected are 8.58 and 8.59. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts). CVSS Vector

CVE-2022-21625
MySQL Server Database
4.4
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.30 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2022-27833
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow.

CVE-2022-36843
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2022 CWE-122 1 PoC

A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

CVE-2022-39860
QuickShare General
4.4
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in QuickShare prior to version 13.2.3.5 allows attackers to access sensitive information via implicit broadcast.

CVE-2022-36844
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2022 CWE-122 1 PoC

A heap-based overflow vulnerability in HWR::EngJudgeModel::Construct() in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

CVE-2022-27574
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

Improper input validation vulnerability in parser_iloc and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by privileged attacker.

CVE-2022-23426
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2022 CWE-94 1 PoC

A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allows attackers to access files with system privilege.

CVE-2022-27837
Accessibility General
4.4
MEDIUM
EPSS
0.2%
2022 CWE-94 1 PoC

A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attacker to access the file with system privilege.

CVE-2022-36863
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2022 CWE-122 1 PoC

A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.

CVE-2022-39897
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2022 CWE-200 1 PoC

Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the kernel address information via log.

CVE-2022-33721
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2022 CWE-94 1 PoC

A vulnerability using PendingIntent in DeX for PC prior to SMR Aug-2022 Release 1 allows attackers to access files with system privilege.

CVE-2022-24413
PowerScale OneFS General
4.4
MEDIUM
EPSS
0.0%
2022 CWE-367 1 PoC

Dell PowerScale OneFS, versions 8.2.2-9.3.x, contain a time-of-check-to-time-of-use vulnerability. A local user with access to the filesystem could potentially exploit this vulnerability, leading to data loss.