Show filters
1,184 Total Results
Displaying 141-150 of 1,184
Sort by:
Attacker Value
Unknown
CVE-2022-0547
Disclosure Date: March 18, 2022 (last updated February 23, 2025)
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.
0
Attacker Value
Unknown
CVE-2022-27191
Disclosure Date: March 18, 2022 (last updated November 08, 2023)
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
0
Attacker Value
Unknown
CVE-2022-24302
Disclosure Date: March 17, 2022 (last updated February 23, 2025)
In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
0
Attacker Value
Unknown
CVE-2021-23648
Disclosure Date: March 16, 2022 (last updated February 23, 2025)
The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
0
Attacker Value
Unknown
CVE-2022-0396
Disclosure Date: March 16, 2022 (last updated February 23, 2025)
BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSE_WAIT status for an indefinite period of time, even after the client has terminated the connection.
0
Attacker Value
Unknown
CVE-2021-25220
Disclosure Date: March 16, 2022 (last updated February 23, 2025)
BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients.
0
Attacker Value
Unknown
CVE-2021-45848
Disclosure Date: March 15, 2022 (last updated February 23, 2025)
Denial of service (DoS) vulnerability in Nicotine+ 3.0.3 and later allows a user with a modified Soulseek client to crash Nicotine+ by sending a file download request with a file path containing a null character.
0
Attacker Value
Unknown
CVE-2022-0943
Disclosure Date: March 14, 2022 (last updated February 23, 2025)
Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563.
0
Attacker Value
Unknown
CVE-2022-22719
Disclosure Date: March 14, 2022 (last updated February 23, 2025)
A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.
0
Attacker Value
Unknown
CVE-2022-22721
Disclosure Date: March 14, 2022 (last updated February 23, 2025)
If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.
0