| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-24528 | Hig | 0.57 | 8.8 | 0.02 | Apr 15, 2022 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | ||
| CVE-2022-24527 | Hig | 0.51 | 7.8 | 0.01 | Apr 15, 2022 | Microsoft Endpoint Configuration Manager Elevation of Privilege Vulnerability | ||
| CVE-2022-24521 | Hig | 0.69 | 7.8 | 0.07 | KEV | Apr 15, 2022 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2022-24513 | Hig | 0.51 | 7.8 | 0.01 | Apr 15, 2022 | Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2022-24500 | Hig | 0.60 | 8.8 | 0.37 | Apr 15, 2022 | Windows SMB Remote Code Execution Vulnerability | ||
| CVE-2022-24499 | Hig | 0.51 | 7.8 | 0.01 | Apr 15, 2022 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2022-24496 | Hig | 0.51 | 7.8 | 0.01 | Apr 15, 2022 | Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | ||
| CVE-2022-24495 | Hig | 0.46 | 7.0 | 0.01 | Apr 15, 2022 | Windows Direct Show Remote Code Execution Vulnerability | ||
| CVE-2022-24494 | Hig | 0.51 | 7.8 | 0.02 | Apr 15, 2022 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | ||
| CVE-2022-24492 | Hig | 0.57 | 8.8 | 0.03 | Apr 15, 2022 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | ||
| CVE-2022-24490 | Hig | 0.53 | 8.1 | 0.03 | Apr 15, 2022 | Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability | ||
| CVE-2022-24489 | Hig | 0.51 | 7.8 | 0.00 | Apr 15, 2022 | Cluster Client Failover (CCF) Elevation of Privilege Vulnerability | ||
| CVE-2022-24488 | Hig | 0.51 | 7.8 | 0.01 | Apr 15, 2022 | Windows Desktop Bridge Elevation of Privilege Vulnerability | ||
| CVE-2022-24487 | Hig | 0.57 | 8.8 | 0.02 | Apr 15, 2022 | Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability | ||
| CVE-2022-24486 | Hig | 0.51 | 7.8 | 0.01 | Apr 15, 2022 | Windows Kerberos Elevation of Privilege Vulnerability | ||
| CVE-2022-24485 | Hig | 0.49 | 7.5 | 0.02 | Apr 15, 2022 | Win32 File Enumeration Remote Code Execution Vulnerability | ||
| CVE-2022-24482 | Hig | 0.46 | 7.0 | 0.00 | Apr 15, 2022 | Windows ALPC Elevation of Privilege Vulnerability | ||
| CVE-2022-24481 | Hig | 0.52 | 7.8 | 0.17 | Apr 15, 2022 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | ||
| CVE-2022-24479 | Hig | 0.51 | 7.8 | 0.01 | Apr 15, 2022 | Connected User Experiences and Telemetry Elevation of Privilege Vulnerability | ||
| CVE-2022-24474 | Hig | 0.51 | 7.8 | 0.07 | Apr 15, 2022 | Windows Win32k Elevation of Privilege Vulnerability | ||
| CVE-2022-24473 | Hig | 0.51 | 7.8 | 0.02 | Apr 15, 2022 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2022-24472 | Hig | 0.52 | 8.0 | 0.02 | Apr 15, 2022 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2022-23259 | Hig | 0.57 | 8.8 | 0.03 | Apr 15, 2022 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | ||
| CVE-2022-23257 | Hig | 0.57 | 8.8 | 0.01 | Apr 15, 2022 | Windows Hyper-V Remote Code Execution Vulnerability | ||
| CVE-2022-22009 | Hig | 0.51 | 7.8 | 0.01 | Apr 15, 2022 | Windows Hyper-V Remote Code Execution Vulnerability | ||
| CVE-2022-22008 | Hig | 0.51 | 7.8 | 0.00 | Apr 15, 2022 | Windows Hyper-V Remote Code Execution Vulnerability | ||
| CVE-2022-21983 | Hig | 0.49 | 7.5 | 0.02 | Apr 15, 2022 | Win32 Stream Enumeration Remote Code Execution Vulnerability | ||
| CVE-2022-27369 | Hig | 0.47 | 7.2 | 0.01 | Apr 15, 2022 | Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component news_News.php_hy. | ||
| CVE-2022-27368 | Hig | 0.47 | 7.2 | 0.01 | Apr 15, 2022 | Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Lists.php_zhuan. | ||
| CVE-2022-27367 | Hig | 0.47 | 7.2 | 0.01 | Apr 15, 2022 | Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Topic.php_del. | ||
| CVE-2022-27366 | Hig | 0.47 | 7.2 | 0.01 | Apr 15, 2022 | Cscms Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the component dance_Dance.php_hy. | ||
| CVE-2022-27365 | Hig | 0.47 | 7.2 | 0.01 | Apr 15, 2022 | Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Dance.php_del. | ||
| CVE-2022-27257 | Hig | 0.49 | 7.5 | 0.01 | Apr 15, 2022 | A PHP Local File Inclusion vulneraility in the default Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files via the schema parameter. | ||
| CVE-2021-44510 | Hig | 0.49 | 7.5 | 0.02 | Apr 15, 2022 | An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c to result in an extremely large value in order to cause a segmentation… | ||
| CVE-2021-44509 | Hig | 0.49 | 7.5 | 0.02 | Apr 15, 2022 | An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause an integer underflow of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c in order to cause a segmentation fault and crash the application. | ||
| CVE-2021-44508 | Hig | 0.49 | 7.5 | 0.02 | Apr 15, 2022 | An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of NULL checks in calls to ious_open in sr_unix/ious_open.c allows attackers to crash the application by dereferencing a NULL pointer. | ||
| CVE-2021-44507 | Hig | 0.49 | 7.5 | 0.02 | Apr 15, 2022 | An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of parameter validation in calls to memcpy in str_tok in sr_unix/ztimeoutroutines.c allows attackers to attempt to read from a NULL pointer. | ||
| CVE-2021-44506 | Hig | 0.49 | 7.5 | 0.02 | Apr 15, 2022 | An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to do_verify in sr_unix/do_verify.c allows attackers to attempt to jump to a NULL pointer by corrupting a function pointer. | ||
| CVE-2021-44505 | Hig | 0.49 | 7.5 | 0.01 | Apr 15, 2022 | An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a NULL pointer dereference after calls to ZPrint. | ||
| CVE-2021-44504 | Hig | 0.49 | 7.5 | 0.02 | Apr 15, 2022 | An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a size variable, stored as an signed int, to equal an extremely large value, which is interpreted as a negative value during a check. This value is… | ||
| CVE-2021-44503 | Hig | 0.49 | 7.5 | 0.02 | Apr 15, 2022 | An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a call to va_arg on an empty variadic parameter list, most likely causing a memory segmentation fault. | ||
| CVE-2021-44502 | Hig | 0.49 | 7.5 | 0.02 | Apr 15, 2022 | An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size of a memset that occurs in calls to util_format in sr_unix/util_output.c. | ||
| CVE-2021-44501 | Hig | 0.49 | 7.5 | 0.02 | Apr 15, 2022 | An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointer dereference. | ||
| CVE-2021-44500 | Hig | 0.49 | 7.5 | 0.02 | Apr 15, 2022 | An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to eb_div in sr_port/eb_muldiv.c allows attackers to crash the application by performing a divide by zero. | ||
| CVE-2021-44499 | Hig | 0.49 | 7.5 | 0.02 | Apr 15, 2022 | An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a call to $Extract to force an signed integer holding the size of a buffer to take on a large negative number, which is then used as the length of… | ||
| CVE-2021-44498 | Hig | 0.49 | 7.5 | 0.02 | Apr 15, 2022 | An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause a type to be incorrectly initialized in the function f_incr in sr_port/f_incr.c and cause a crash due to a NULL pointer dereference. | ||
| CVE-2021-44497 | Hig | 0.49 | 7.5 | 0.01 | Apr 15, 2022 | An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, can cause the bounds of a for loop to be miscalculated, which leads to a use after free condition a pointer is pushed into previously free memory by the loop. | ||
| CVE-2021-44495 | Hig | 0.49 | 7.5 | 0.01 | Apr 15, 2022 | An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause a NULL pointer dereference after calls to ZPrint. | ||
| CVE-2021-44494 | Hig | 0.49 | 7.5 | 0.01 | Apr 15, 2022 | An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointer dereference. | ||
| CVE-2021-44493 | Hig | 0.49 | 7.5 | 0.02 | Apr 15, 2022 | An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause a call to $Extract to force an signed integer holding the size of a buffer to take on a large negative number, which is then used as the length… |
- risk 0.57cvss 8.8epss 0.02
Remote Procedure Call Runtime Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Endpoint Configuration Manager Elevation of Privilege Vulnerability
- risk 0.69cvss 7.8epss 0.07
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Visual Studio Elevation of Privilege Vulnerability
- risk 0.60cvss 8.8epss 0.37
Windows SMB Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Installer Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Direct Show Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.02
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.03
Remote Procedure Call Runtime Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.03
Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability
- risk 0.51cvss 7.8epss 0.00
Cluster Client Failover (CCF) Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Desktop Bridge Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Kerberos Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.02
Win32 File Enumeration Remote Code Execution Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows ALPC Elevation of Privilege Vulnerability
- risk 0.52cvss 7.8epss 0.17
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.07
Windows Win32k Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.02
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.52cvss 8.0epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.57cvss 8.8epss 0.03
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
Windows Hyper-V Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Hyper-V Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Hyper-V Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.02
Win32 Stream Enumeration Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.01
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component news_News.php_hy.
- risk 0.47cvss 7.2epss 0.01
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Lists.php_zhuan.
- risk 0.47cvss 7.2epss 0.01
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Topic.php_del.
- risk 0.47cvss 7.2epss 0.01
Cscms Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the component dance_Dance.php_hy.
- risk 0.47cvss 7.2epss 0.01
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Dance.php_del.
- risk 0.49cvss 7.5epss 0.01
A PHP Local File Inclusion vulneraility in the default Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files via the schema parameter.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c to result in an extremely large value in order to cause a segmentation…
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause an integer underflow of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c in order to cause a segmentation fault and crash the application.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of NULL checks in calls to ious_open in sr_unix/ious_open.c allows attackers to crash the application by dereferencing a NULL pointer.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of parameter validation in calls to memcpy in str_tok in sr_unix/ztimeoutroutines.c allows attackers to attempt to read from a NULL pointer.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to do_verify in sr_unix/do_verify.c allows attackers to attempt to jump to a NULL pointer by corrupting a function pointer.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a NULL pointer dereference after calls to ZPrint.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a size variable, stored as an signed int, to equal an extremely large value, which is interpreted as a negative value during a check. This value is…
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a call to va_arg on an empty variadic parameter list, most likely causing a memory segmentation fault.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size of a memset that occurs in calls to util_format in sr_unix/util_output.c.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointer dereference.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to eb_div in sr_port/eb_muldiv.c allows attackers to crash the application by performing a divide by zero.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a call to $Extract to force an signed integer holding the size of a buffer to take on a large negative number, which is then used as the length of…
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause a type to be incorrectly initialized in the function f_incr in sr_port/f_incr.c and cause a crash due to a NULL pointer dereference.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, can cause the bounds of a for loop to be miscalculated, which leads to a use after free condition a pointer is pushed into previously free memory by the loop.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause a NULL pointer dereference after calls to ZPrint.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointer dereference.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause a call to $Extract to force an signed integer holding the size of a buffer to take on a large negative number, which is then used as the length…