7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-37386
PDF Reader Web
3.3
LOW
EPSS
0.9%
2022 CWE-125 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.2.53575. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the resetForm method. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17550.

CVE-2022-30729
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-923 1 PoC

Implicit Intent hijacking vulnerability in Settings prior to SMR Jun-2022 Release 1 allows attackers to get Wi-Fi SSID and password via a malicious QR code scanner.

CVE-2022-24736
redis Database
3.3
LOW
EPSS
1.7%
2022 CWE-476 1 PoC

Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to `SCRIPT LOAD` and `EVAL` commands using ACL rules.

CVE-2022-30753
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-200 1 PoC

Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers to get the device ID without permission.

CVE-2022-30742
Find My Mobile General
3.3
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Sensitive information exposure vulnerability in FmmExtraOperation of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permissio to get sim card information through device log.

CVE-2022-30749
Smart Things General
3.3
LOW
EPSS
0.0%
2022 CWE-287 1 PoC

Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity.

CVE-2022-39864
SmartThings General
3.3
LOW
EPSS
0.2%
2022 CWE-284 1 PoC

Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive information via implicit intent.

CVE-2022-33697
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-532 1 PoC

Sensitive information exposure vulnerability in ImsServiceSwitchBase in ImsCore prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.

CVE-2022-37379
PDF Reader General
3.3
LOW
EPSS
0.9%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the AFSpecial_KeystrokeEx method. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current pr

CVE-2022-33701
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to call PowerManaer.goToSleep method which is protected by system permission by sending braodcast intent.

CVE-2022-36853
Samsung Mobile Devices General
3.3
LOW
EPSS
0.1%
2022 CWE-20 1 PoC

Intent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive information.

CVE-2022-25833
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-287 1 PoC

Improper authentication in ImsService prior to SMR Apr-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission.

CVE-2022-36878
Find My Mobile General
3.3
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Exposure of Sensitive Information in Find My Mobile prior to version 7.2.25.14 allows local attacker to access IMEI via log.

CVE-2022-28764
Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) Database Windows
3.3
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a local information exposure vulnerability. A failure to clear data from a local SQL database after a meeting ends and the usage of an insufficiently secure per-device key encrypting that database results in a local malicious user being able to obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.

CVE-2022-33688
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-532 1 PoC

Sensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.

CVE-2022-28670
PDF Reader General
3.3
LOW
EPSS
0.2%
2022 CWE-125 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of AcroForms. Crafted data in an AcroForm can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16523.

CVE-2022-34873
PDF Reader Web
3.3
LOW
EPSS
0.7%
2022 CWE-125 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16777.

CVE-2022-2227
GitLab DevOps Web
3.1
LOW
EPSS
0.2%
2022 1 PoC

Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions

CVE-2022-4045
Mattermost Web
3.1
LOW
EPSS
0.5%
2022 CWE-770 1 PoC

A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoints which could fetch a large amount of data. 

CVE-2022-3257
Mattermost General
3.1
LOW
EPSS
0.4%
2022 CWE-400 1 PoC

Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.