Show filters
264 Total Results
Displaying 11-20 of 264
Sort by:
Attacker Value
Unknown
CVE-2022-29885
Disclosure Date: May 12, 2022 (last updated November 29, 2024)
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.
0
Attacker Value
Unknown
CVE-2018-25032
Disclosure Date: March 25, 2022 (last updated November 08, 2023)
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
0
Attacker Value
Unknown
CVE-2022-22719
Disclosure Date: March 14, 2022 (last updated November 08, 2023)
A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.
0
Attacker Value
Unknown
CVE-2022-22721
Disclosure Date: March 14, 2022 (last updated November 08, 2023)
If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.
0
Attacker Value
Unknown
CVE-2022-23308
Disclosure Date: February 26, 2022 (last updated November 08, 2023)
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
0
Attacker Value
Unknown
CVE-2021-45444
Disclosure Date: February 14, 2022 (last updated October 07, 2023)
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
0
Attacker Value
Unknown
CVE-2022-0530
Disclosure Date: February 09, 2022 (last updated October 07, 2023)
A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
0
Attacker Value
Unknown
CVE-2022-23181
Disclosure Date: January 27, 2022 (last updated November 29, 2024)
The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.
0
Attacker Value
Unknown
CVE-2022-0261
Disclosure Date: January 18, 2022 (last updated November 08, 2023)
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
0
Attacker Value
Unknown
CVE-2021-4193
Disclosure Date: December 31, 2021 (last updated November 08, 2023)
vim is vulnerable to Out-of-bounds Read
0