Show filters
1,624 Total Results
Displaying 581-590 of 1,624
Sort by:
Attacker Value
Unknown

CVE-2022-42418

Disclosure Date: January 26, 2023 (last updated February 24, 2025)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. The issue results from the lack of proper validation of a user-supplied value prior to dereferencing it as a pointer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18677.
Attacker Value
Unknown

CVE-2022-42396

Disclosure Date: January 26, 2023 (last updated February 24, 2025)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XPS files. The issue results from the lack of proper validation of a user-supplied value prior to dereferencing it as a pointer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18278.
Attacker Value
Unknown

CVE-2022-42377

Disclosure Date: January 26, 2023 (last updated February 24, 2025)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18630.
Attacker Value
Unknown

CVE-2022-34399

Disclosure Date: January 18, 2023 (last updated February 24, 2025)
Dell Alienware m17 R5 BIOS version prior to 1.2.2 contain a buffer access vulnerability. A malicious user with admin privileges could potentially exploit this vulnerability by sending input larger than expected in order to leak certain sections of SMRAM.
Attacker Value
Unknown

CVE-2022-42286

Disclosure Date: January 13, 2023 (last updated February 24, 2025)
DGX A100 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of service, or escalation of privileges.
Attacker Value
Unknown

CVE-2022-42278

Disclosure Date: January 13, 2023 (last updated February 24, 2025)
NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can read and write to arbitrary locations within the memory context of the IPMI server process, which may lead to code execution, denial of service, information disclosure and data tampering.
Attacker Value
Unknown

CVE-2022-3161

Disclosure Date: January 13, 2023 (last updated February 24, 2025)
The APDFL.dll contains a memory corruption vulnerability while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
Attacker Value
Unknown

CVE-2023-23457

Disclosure Date: January 12, 2023 (last updated February 24, 2025)
A Segmentation fault was found in UPX in PackLinuxElf64::invert_pt_dynamic() in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.
Attacker Value
Unknown

CVE-2022-3628

Disclosure Date: January 12, 2023 (last updated February 24, 2025)
A buffer overflow flaw was found in the Linux kernel Broadcom Full MAC Wi-Fi driver. This issue occurs when a user connects to a malicious USB device. This can allow a local user to crash the system or escalate their privileges.
Attacker Value
Unknown

CVE-2023-20531

Disclosure Date: January 11, 2023 (last updated February 24, 2025)
Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service.