Show filters
1,184 Total Results
Displaying 191-200 of 1,184
Sort by:
Attacker Value
Unknown

CVE-2021-3607

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest due to improper input validation. This flaw allows a privileged guest user to make QEMU allocate a large amount of memory, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2021-25636

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.
Attacker Value
Unknown

CVE-2019-25058

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future.
Attacker Value
Unknown

CVE-2022-24407

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
Attacker Value
Unknown

CVE-2022-0729

Disclosure Date: February 23, 2022 (last updated February 23, 2025)
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.
Attacker Value
Unknown

CVE-2022-0714

Disclosure Date: February 22, 2022 (last updated February 23, 2025)
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.
Attacker Value
Unknown

CVE-2022-25600

Disclosure Date: February 22, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).
Attacker Value
Unknown

CVE-2021-4115

Disclosure Date: February 21, 2022 (last updated February 23, 2025)
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned
Attacker Value
Unknown

CVE-2022-0696

Disclosure Date: February 21, 2022 (last updated February 23, 2025)
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.
Attacker Value
Unknown

CVE-2021-44141

Disclosure Date: February 21, 2022 (last updated February 23, 2025)
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be enabled in order for this attack to succeed.