VYPR

CVEs

101,988 total · page 1198 of 2,040

  • CVE-2022-0310HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in Task Manager in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via specific user interactions.

  • CVE-2022-0308HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Data Transfer in Google Chrome on Chrome OS prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0307HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Optimization Guide in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0306HigFeb 12, 2022
    risk 0.64cvss 8.8epss 0.85

    Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0304HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Bookmarks in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0302HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed an attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0301HigFeb 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Heap buffer overflow in DevTools in Google Chrome prior to 97.0.4692.99 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0300HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Text Input Method Editor in Google Chrome on Android prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0298HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Scheduling in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0297HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Vulkan in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0296HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Printing in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced the user to engage is specific user interactions to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0295HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced the user to engage is specific user interactions to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0293HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Web packaging in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0289HigFeb 12, 2022
    risk 0.59cvss 8.8epss 0.28

    Use after free in Safe browsing in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0115HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Uninitialized use in File API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

  • CVE-2022-0114HigFeb 12, 2022
    risk 0.53cvss 8.1epss 0.01

    Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page and virtual serial port driver.

  • CVE-2022-0107HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in File Manager API in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0106HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0105HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in PDF Accessibility in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0104HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in ANGLE in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0103HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in SwiftShader in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0102HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Type confusion in V8 in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0101HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in Bookmarks in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to potentially exploit heap corruption via specific user gesture.

  • CVE-2022-0100HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in Media streams API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0099HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Sign-in in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gestures to potentially exploit heap corruption via specific user gesture.

  • CVE-2022-0098HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Screen Capture in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to perform specific user gestures to potentially exploit heap corruption via specific user gestures.

  • CVE-2022-0096HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Storage in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-4102HigKEVFeb 11, 2022
    risk 0.70cvss 8.8epss 0.08

    Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-4101HigFeb 11, 2022
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-4100HigFeb 11, 2022
    risk 0.57cvss 8.8epss 0.01

    Object lifecycle issue in ANGLE in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-4099HigFeb 11, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-4098HigFeb 11, 2022
    risk 0.48cvss 7.4epss 0.01

    Insufficient data validation in Mojo in Google Chrome prior to 96.0.4664.110 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2022-23634HigFeb 11, 2022
    risk 0.45cvss 8.0epss 0.02

    Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5.6.2`, `puma` may not always call `close` on the response body. Rails, prior to version `7.0.2.2`, depended on the response body being closed in order for its `CurrentAttributes` implementation to…

  • CVE-2022-23633HigFeb 11, 2022
    risk 0.41cvss 7.4epss 0.02

    Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next…

  • CVE-2021-46366HigFeb 11, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Forgery (CSRF) in order to brute force and exfiltrate users' credentials.

  • CVE-2021-46365HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.02

    An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file.

  • CVE-2021-46364HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.02

    A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML file.

  • CVE-2021-46363HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.02

    An issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via crafted CSV/XLS files. These formulas may result in arbitrary code execution on a victim's computer when opening the exported files with Microsoft Excel.

  • CVE-2022-24975HigFeb 11, 2022
    risk 0.49cvss 7.5epss 0.03

    The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has…

  • CVE-2022-22766HigFeb 11, 2022
    risk 0.46cvss 7.0epss 0.00

    Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access…

  • CVE-2022-23853HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.01

    The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary when opening a file of a given type. If this binary is absent from the PATH, it will try running the LSP server binary in the…

  • CVE-2022-23428HigFeb 11, 2022
    risk 0.55cvss 8.4epss 0.00

    An improper boundary check in eden_runtime hal service prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.

  • CVE-2022-23425HigFeb 11, 2022
    risk 0.56cvss 8.6epss 0.00

    Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base station.

  • CVE-2022-22292HigFeb 11, 2022
    risk 0.46cvss 7.1epss 0.00

    Unprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted applications to launch arbitrary activity.

  • CVE-2022-0483HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53

  • CVE-2022-0185HigKEVFeb 11, 2022
    risk 0.14cvss 8.4epss 0.25

    A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs…

  • CVE-2021-39677HigFeb 11, 2022
    risk 0.49cvss 7.5epss 0.00

    In startVideoStream() there is a possibility of an OOB Read in the heap, when the camera buffer is ‘zero’ in size.Product: AndroidVersions: Android-11Android ID: A-205097028

  • CVE-2021-39676HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-39674HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    In btm_sec_connected and btm_sec_disconnected of btm_sec.cc file , there is a possible use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10…

  • CVE-2021-39672HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    In fastboot, there is a possible secure boot bypass due to a configuration error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android SoC Android ID:…