Show filters
666 Total Results
Displaying 91-100 of 666
Sort by:
Attacker Value
Unknown

CVE-2022-22976

Disclosure Date: May 19, 2022 (last updated February 23, 2025)
Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.
Attacker Value
Unknown

CVE-2022-1116

Disclosure Date: May 17, 2022 (last updated February 23, 2025)
Integer Overflow or Wraparound vulnerability in io_uring of Linux Kernel allows local attacker to cause memory corruption and escalate privileges to root. This issue affects: Linux Kernel versions prior to 5.4.189; version 5.4.24 and later versions.
Attacker Value
Unknown

CVE-2022-1728

Disclosure Date: May 16, 2022 (last updated February 23, 2025)
Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.
Attacker Value
Unknown

CVE-2022-28937

Disclosure Date: May 15, 2022 (last updated February 23, 2025)
FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node, via an invalid proposal with an invalid header, will cause normal nodes to stop producing new blocks and processing new clients' requests.
Attacker Value
Unknown

CVE-2022-28936

Disclosure Date: May 15, 2022 (last updated February 23, 2025)
FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node can trigger an integer overflow and cause a Denial of Service (DoS) via an unusually large viewchange message packet.
Attacker Value
Unknown

CVE-2022-1699

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Uncontrolled Resource Consumption in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.
Attacker Value
Unknown

CVE-2022-27114

Disclosure Date: May 09, 2022 (last updated February 23, 2025)
There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and 'img->height' they are large enough to cause an integer overflow. So, the malloc function may return a heap blosmaller than the expected size, and it will cause a buffer overflow/Address boundary error in the jpeg_read_scanlines function.
Attacker Value
Unknown

CVE-2022-28471

Disclosure Date: May 05, 2022 (last updated February 23, 2025)
In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eventually results in the heap overflow in jfif_encode() in jfif.c. This is due to the incomplete patch for issue 38
Attacker Value
Unknown

CVE-2022-26073

Disclosure Date: May 05, 2022 (last updated February 23, 2025)
A denial of service vulnerability exists in the libxm_av.so DemuxCmdInBuffer functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to a device reboot. An attacker can send packets to trigger this vulnerability.
Attacker Value
Unknown

CVE-2022-28705

Disclosure Date: May 04, 2022 (last updated February 23, 2025)
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, on platforms with an ePVA and the pva.fwdaccel BigDB variable enabled, undisclosed requests to a virtual server with a FastL4 profile that has ePVA acceleration enabled can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated