Show filters
305 Total Results
Displaying 161-170 of 305
Sort by:
Attacker Value
Unknown

CVE-2022-24373

Disclosure Date: September 30, 2022 (last updated February 24, 2025)
The package react-native-reanimated before 3.0.0-rc.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper usage of regular expression in the parser of Colors.js.
Attacker Value
Unknown

CVE-2022-38411

Disclosure Date: September 13, 2022 (last updated February 24, 2025)
Adobe Animate version 21.0.11 (and earlier) and 22.0.7 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Attacker Value
Unknown

CVE-2022-38412

Disclosure Date: September 13, 2022 (last updated February 24, 2025)
Adobe Animate version 21.0.11 (and earlier) and 22.0.7 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Attacker Value
Unknown

CVE-2022-34241

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Adobe Character Animator version 4.4.7 (and earlier) and 22.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Attacker Value
Unknown

CVE-2022-34242

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Adobe Character Animator version 4.4.7 (and earlier) and 22.4 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Attacker Value
Unknown

CVE-2022-31511

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The AFDudley/equanimity repository through 2014-04-23 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Attacker Value
Unknown

CVE-2022-30664

Disclosure Date: June 14, 2022 (last updated February 23, 2025)
Adobe Animate version 22.0.5 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
0
Attacker Value
Unknown

CVE-2022-24967

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Black Rainbow NIMBUS before 3.7.0 allows stored Cross-site Scripting (XSS).
Attacker Value
Unknown

CVE-2022-31500

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions.
Attacker Value
Unknown

CVE-2022-28618

Disclosure Date: May 20, 2022 (last updated February 23, 2025)
A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to execute arbitrary commands on a Nimble appliance. HPE has made the following software updates to resolve the vulnerability in HPE Nimble Storage: 5.0.10.100 or later, 5.2.1.0 or later, 6.0.0.100 or later.