Show filters
306 Total Results
Displaying 121-130 of 306
Sort by:
Attacker Value
Unknown

CVE-2021-26635

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
In the code that verifies the file size in the ark library, it is possible to manipulate the offset read from the target file due to the wrong use of the data type. An attacker could use this vulnerability to cause a stack buffer overflow and as a result, perform an attack such as remote code execution.
Attacker Value
Unknown

CVE-2022-1786

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
A use-after-free flaw was found in the Linux kernel’s io_uring subsystem in the way a user sets up a ring with IORING_SETUP_IOPOLL with more than one task completing submissions on this ring. This flaw allows a local user to crash or escalate their privileges on the system.
Attacker Value
Unknown

CVE-2022-31007

Disclosure Date: May 31, 2022 (last updated February 23, 2025)
eLabFTW is an electronic lab notebook manager for research teams. Prior to version 4.3.0, a vulnerability allows an authenticated user with an administrator role in a team to assign itself system administrator privileges within the application, or create a new system administrator account. The issue has been corrected in eLabFTW version 4.3.0. In the context of eLabFTW, an administrator is a user account with certain privileges to manage users and content in their assigned team/teams. A system administrator account can manage all accounts, teams and edit system-wide settings within the application. The impact is not deemed as high, as it requires the attacker to have access to an administrator account. Regular user accounts cannot exploit this to gain admin rights. A workaround for one if the issues is removing the ability of administrators to create accounts.
Attacker Value
Unknown

CVE-2021-32965

Disclosure Date: May 24, 2022 (last updated February 23, 2025)
Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to type confusion, which may allow an attacker to remotely execute arbitrary code.
Attacker Value
Unknown

CVE-2022-1848

Disclosure Date: May 24, 2022 (last updated February 23, 2025)
Business Logic Errors in GitHub repository erudika/para prior to 1.45.11.
Attacker Value
Unknown

CVE-2022-29209

Disclosure Date: May 21, 2022 (last updated February 23, 2025)
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the macros that TensorFlow uses for writing assertions (e.g., `CHECK_LT`, `CHECK_GT`, etc.) have an incorrect logic when comparing `size_t` and `int` values. Due to type conversion rules, several of the macros would trigger incorrectly. Versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4 contain a patch for this issue.
Attacker Value
Unknown

CVE-2022-29181

Disclosure Date: May 20, 2022 (last updated February 23, 2025)
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated memory. Version 1.13.6 contains a patch for this issue. As a workaround, ensure the untrusted input is a `String` by calling `#to_s` or equivalent.
Attacker Value
Unknown

CVE-2022-30557

Disclosure Date: May 11, 2022 (last updated February 23, 2025)
Foxit PDF Reader and PDF Editor before 11.2.2 have a Type Confusion issue that causes a crash because of Unsigned32 mishandling during JavaScript execution.
Attacker Value
Unknown

CVE-2021-41041

Disclosure Date: April 27, 2022 (last updated February 23, 2025)
In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered by a MethodHandle invocation, allowing unverified methods to be invoked using MethodHandles.
Attacker Value
Unknown

CVE-2022-0935

Disclosure Date: April 07, 2022 (last updated February 23, 2025)
Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97.