Show filters
1,184 Total Results
Displaying 271-280 of 1,184
Sort by:
Attacker Value
Unknown

CVE-2022-23833

Disclosure Date: February 03, 2022 (last updated February 23, 2025)
An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.
Attacker Value
Unknown

CVE-2022-0443

Disclosure Date: February 02, 2022 (last updated February 23, 2025)
Use After Free in GitHub repository vim/vim prior to 8.2.
Attacker Value
Unknown

CVE-2022-24917

Disclosure Date: February 02, 2022 (last updated February 23, 2025)
An authenticated user can create a link with reflected Javascript code inside it for services’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim during social engineering attacks.
Attacker Value
Unknown

CVE-2022-0417

Disclosure Date: February 01, 2022 (last updated February 23, 2025)
Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.
Attacker Value
Unknown

CVE-2021-43859

Disclosure Date: February 01, 2022 (last updated February 23, 2025)
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.
Attacker Value
Unknown

CVE-2022-0419

Disclosure Date: February 01, 2022 (last updated February 23, 2025)
NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.
Attacker Value
Unknown

CVE-2022-24919

Disclosure Date: February 01, 2022 (last updated February 23, 2025)
An authenticated user can create a link with reflected Javascript code inside it for graphs’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim during social engineering attacks.
Attacker Value
Unknown

CVE-2022-24349

Disclosure Date: February 01, 2022 (last updated February 23, 2025)
An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim. This attack can be implemented with the help of social engineering and expiration of a number of factors - an attacker should have authorized access to the Zabbix Frontend and allowed network connection between a malicious server and victim’s computer, understand attacked infrastructure, be recognized by the victim as a trustee and use trusted communication channel.
Attacker Value
Unknown

CVE-2022-24918

Disclosure Date: February 01, 2022 (last updated February 23, 2025)
An authenticated user can create a link with reflected Javascript code inside it for items’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim during social engineering attacks.
Attacker Value
Unknown

CVE-2021-46668

Disclosure Date: February 01, 2022 (last updated February 23, 2025)
MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.