Show filters
820 Total Results
Displaying 241-250 of 820
Sort by:
Attacker Value
Unknown
CVE-2015-20107
Disclosure Date: April 13, 2022 (last updated February 23, 2025)
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9
0
Attacker Value
Unknown
CVE-2022-28796
Disclosure Date: April 08, 2022 (last updated February 23, 2025)
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
0
Attacker Value
Unknown
CVE-2022-1056
Disclosure Date: March 28, 2022 (last updated February 23, 2025)
Out-of-bounds Read error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 46dc8fcd.
0
Attacker Value
Unknown
CVE-2021-4203
Disclosure Date: March 25, 2022 (last updated February 23, 2025)
A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges may crash the system or leak internal kernel information.
0
Attacker Value
Unknown
CVE-2018-25032
Disclosure Date: March 25, 2022 (last updated February 23, 2025)
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
0
Attacker Value
Unknown
CVE-2022-27223
Disclosure Date: March 16, 2022 (last updated February 23, 2025)
In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access.
0
Attacker Value
Unknown
CVE-2022-26966
Disclosure Date: March 12, 2022 (last updated October 07, 2023)
An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitive information from heap memory via crafted frame lengths from a device.
0
Attacker Value
Unknown
CVE-2020-36518
Disclosure Date: March 11, 2022 (last updated February 23, 2025)
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
0
Attacker Value
Unknown
CVE-2022-26488
Disclosure Date: March 10, 2022 (last updated February 23, 2025)
In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may allow a local attacker to add user-writable directories to the system search path. To exploit, an administrator must have installed Python for all users and enabled PATH entries. A non-administrative user can trigger a repair that incorrectly adds user-writable paths into PATH, enabling search-path hijacking of other users and system services. This affects Python (CPython) through 3.7.12, 3.8.x through 3.8.12, 3.9.x through 3.9.10, and 3.10.x through 3.10.2.
0
Attacker Value
Unknown
CVE-2022-0891
Disclosure Date: March 10, 2022 (last updated February 23, 2025)
A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact
0