Show filters
1,878 Total Results
Displaying 191-200 of 1,878
Sort by:
Attacker Value
Unknown
CVE-2021-3669
Disclosure Date: August 26, 2022 (last updated February 24, 2025)
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
0
Attacker Value
Unknown
CVE-2021-20316
Disclosure Date: August 23, 2022 (last updated February 24, 2025)
A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share.
0
Attacker Value
Unknown
CVE-2021-3659
Disclosure Date: August 22, 2022 (last updated February 24, 2025)
A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash the system. The highest threat from this vulnerability is to system availability.
0
Attacker Value
Unknown
CVE-2022-26373
Disclosure Date: August 18, 2022 (last updated November 29, 2024)
Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.
0
Attacker Value
Unknown
CVE-2022-31197
Disclosure Date: August 03, 2022 (last updated February 24, 2025)
PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method is not performing escaping of column names so a malicious column name that contains a statement terminator, e.g. `;`, could lead to SQL injection. This could lead to executing additional SQL commands as the application's JDBC user. User applications that do not invoke the `ResultSet.refreshRow()` method are not impacted. User application that do invoke that method are impacted if the underlying database that they are querying via their JDBC application may be under the control of an attacker. The attack requires the attacker to trick the user into executing SQL against a table name who's column names would contain the malicious SQL and subsequently invoke the `refreshRow()` method on the ResultSet. Note that the application's JDBC user and the schema owner need not be…
0
Attacker Value
Unknown
CVE-2022-34526
Disclosure Date: July 29, 2022 (last updated February 24, 2025)
A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted TIFF file parsed by the "tiffsplit" or "tiffcrop" utilities.
0
Attacker Value
Unknown
CVE-2022-35653
Disclosure Date: July 25, 2022 (last updated February 24, 2025)
A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.
0
Attacker Value
Unknown
CVE-2022-35651
Disclosure Date: July 25, 2022 (last updated February 24, 2025)
A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks.
0
Attacker Value
Unknown
CVE-2022-23825
Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.
0
Attacker Value
Unknown
CVE-2022-29900
Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.
0