Show filters
310 Total Results
Displaying 101-110 of 310
Sort by:
Attacker Value
Unknown
CVE-2022-43680
Disclosure Date: October 24, 2022 (last updated February 24, 2025)
In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.
0
Attacker Value
Unknown
CVE-2022-3649
Disclosure Date: October 21, 2022 (last updated February 24, 2025)
A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_new_inode of the file fs/nilfs2/inode.c of the component BPF. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211992.
0
Attacker Value
Unknown
CVE-2022-3564
Disclosure Date: October 17, 2022 (last updated February 24, 2025)
A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211087.
0
Attacker Value
Unknown
CVE-2022-3545
Disclosure Date: October 17, 2022 (last updated February 24, 2025)
A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerability is the function area_cache_get of the file drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier VDB-211045 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-35252
Disclosure Date: September 23, 2022 (last updated February 24, 2025)
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.
0
Attacker Value
Unknown
CVE-2022-41222
Disclosure Date: September 21, 2022 (last updated February 24, 2025)
mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move.
0
Attacker Value
Unknown
CVE-2022-3202
Disclosure Date: September 14, 2022 (last updated February 24, 2025)
A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This could allow a local attacker to crash the system or leak kernel internal information.
0
Attacker Value
Unknown
CVE-2022-2964
Disclosure Date: September 09, 2022 (last updated February 24, 2025)
A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes.
0
Attacker Value
Unknown
CVE-2022-2526
Disclosure Date: September 09, 2022 (last updated February 24, 2025)
A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.
0
Attacker Value
Unknown
CVE-2022-1729
Disclosure Date: September 01, 2022 (last updated February 24, 2025)
A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit primitives such as kernel address information leak, arbitrary execution, etc.
0