Show filters
6,913 Total Results
Displaying 81-90 of 6,913
Sort by:
Attacker Value
Unknown
CVE-2022-37452
Disclosure Date: August 07, 2022 (last updated February 24, 2025)
Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.
1
Attacker Value
Unknown
CVE-2022-2274
Disclosure Date: June 09, 2022 (last updated February 24, 2025)
The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation. As a consequence of the memory corruption an attacker may be able to trigger a remote code execution on the machine performing the computation. SSL/TLS servers or other servers using 2048 bit RSA private keys running on machines supporting AVX512IFMA instructions of the X86_64 architecture are affected by this issue.
1
Attacker Value
Unknown
CVE-2022-29072
Disclosure Date: April 15, 2022 (last updated February 23, 2025)
7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process under the 7zFM.exe process. NOTE: multiple third parties have reported that no privilege escalation can occur
1
Attacker Value
Unknown
CVE-2022-24521
Disclosure Date: April 15, 2022 (last updated February 23, 2025)
Windows Common Log File System Driver Elevation of Privilege Vulnerability
1
Attacker Value
Unknown
CVE-2022-28381
Disclosure Date: April 03, 2022 (last updated February 23, 2025)
Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a long string to TCP port 888, a related issue to CVE-2017-17932.
1
Attacker Value
Unknown
CVE-2022-20700
Disclosure Date: February 03, 2022 (last updated February 23, 2025)
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.
1
Attacker Value
Unknown
CVE-2021-4079
Disclosure Date: December 23, 2021 (last updated February 23, 2025)
Out of bounds write in WebRTC in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via crafted WebRTC packets.
1
Attacker Value
Unknown
CVE-2021-44790
Disclosure Date: December 20, 2021 (last updated February 23, 2025)
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.
1
Attacker Value
Unknown
CVE-2021-3060
Disclosure Date: November 10, 2021 (last updated February 23, 2025)
An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root user privileges. The attacker must have network access to the GlobalProtect interfaces to exploit this issue. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20-h1; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14-h3; PAN-OS 9.1 versions earlier than PAN-OS 9.1.11-h2; PAN-OS 10.0 versions earlier than PAN-OS 10.0.8; PAN-OS 10.1 versions earlier than PAN-OS 10.1.3. Prisma Access customers with Prisma Access 2.1 Preferred and Prisma Access 2.1 Innovation firewalls are impacted by this issue.
1
Attacker Value
Unknown
CVE-2021-30632
Disclosure Date: October 08, 2021 (last updated February 23, 2025)
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
1