VYPR

CVEs

38,096 total · page 418 of 762

  • CVE-2022-34470CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

  • CVE-2022-31748CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Mozilla developers Gabriele Svelto, Timothy Nikkel, Randell Jesup, Jon Coppeard, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could…

  • CVE-2022-31747CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox ESR 91.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have…

  • CVE-2022-31737CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

  • CVE-2022-31736CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

  • CVE-2022-29917CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99 and Firefox ESR 91.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…

  • CVE-2022-26486CriKEVDec 22, 2022
    risk 0.75cvss 9.6epss 0.02

    An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0,…

  • CVE-2022-26384CriDec 22, 2022
    risk 0.62cvss 9.6epss 0.01

    If an attacker could control the contents of an iframe sandboxed with allow-popups but not allow-scripts, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox. This vulnerability affects…

  • CVE-2022-22759CriDec 22, 2022
    risk 0.62cvss 9.6epss 0.01

    If a document created a sandboxed iframe without allow-scripts, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox…

  • CVE-2022-1887CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101.

  • CVE-2021-4140CriDec 22, 2022
    risk 0.65cvss 10.0epss 0.01

    It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

  • CVE-2021-4129CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported memory safety bugs present in Firefox 94. Some of these bugs showed evidence of memory corruption and we presume that with enough…

  • CVE-2021-4127CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects Thunderbird < 78.9 and Firefox ESR < 78.9.

  • CVE-2022-47926CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php

  • CVE-2022-46102CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php

  • CVE-2022-45966CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5.

  • CVE-2022-45347CriDec 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session completely after client authentication failed, which allowed an attacker to execute normal commands by constructing a special MySQL client. This vulnerability has…

  • CVE-2022-3184CriDec 21, 2022
    risk 0.65cvss 9.8epss 0.12

    Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to access an old PHP page vulnerable to directory traversal, which may allow a user to write a file to the webroot directory.

  • CVE-2022-3183CriDec 21, 2022
    risk 0.64cvss 9.8epss 0.02

    Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability.

  • CVE-2022-40145CriDec 21, 2022
    risk 0.57cvss 9.8epss 0.03

    This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialContext.lookup(jndiName)…

  • CVE-2022-47635CriDec 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Wildix WMS 6 before 6.02.20221216, WMS 5 before 5.04.20221214, and WMS4 before 4.04.45396.23 allows Server-side request forgery (SSRF) via ZohoClient.php.

  • CVE-2022-25893CriDec 21, 2022
    risk 0.64cvss 9.8epss 0.01

    The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the WeakMap.prototype.set method. Exploiting this vulnerability leads to access to a host object and a sandbox compromise.

  • CVE-2022-47629CriDec 20, 2022
    risk 0.64cvss 9.8epss 0.02

    Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.

  • CVE-2022-46327CriDec 20, 2022
    risk 0.64cvss 9.8epss 0.00

    Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in system service exceptions.

  • CVE-2022-46326CriDec 20, 2022
    risk 0.64cvss 9.8epss 0.01

    Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.

  • CVE-2022-46325CriDec 20, 2022
    risk 0.64cvss 9.8epss 0.01

    Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.

  • CVE-2022-46324CriDec 20, 2022
    risk 0.64cvss 9.8epss 0.01

    Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.

  • CVE-2022-46323CriDec 20, 2022
    risk 0.64cvss 9.8epss 0.01

    Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.

  • CVE-2022-46320CriDec 20, 2022
    risk 0.64cvss 9.8epss 0.01

    The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may cause memory overwriting.

  • CVE-2022-46319CriDec 20, 2022
    risk 0.64cvss 9.8epss 0.01

    Fingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability may cause out-of-bounds write.

  • CVE-2022-46316CriDec 20, 2022
    risk 0.64cvss 9.8epss 0.01

    A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.

  • CVE-2022-46020CriDec 20, 2022
    risk 0.67cvss 9.8epss 0.39

    WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.

  • CVE-2022-46538CriDec 20, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac.

  • CVE-2022-40624CriDec 20, 2022
    risk 0.65cvss 9.8epss 0.17

    pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.

  • CVE-2022-46421CriDec 20, 2022
    risk 0.57cvss 9.8epss 0.03

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0.

  • CVE-2022-44109CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    pdftojson commit 94204bb was discovered to contain a stack overflow via the component Stream::makeFilter(char*, Stream*, Object*, int).

  • CVE-2022-44108CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    pdftojson commit 94204bb was discovered to contain a stack overflow via the component Object::copy(Object*):Object.cc.

  • CVE-2022-44940CriDec 19, 2022
    risk 0.52cvss 9.1epss 0.01

    Patchelf v0.9 was discovered to contain an out-of-bounds read via the function modifyRPath at src/patchelf.cc.

  • CVE-2022-40434CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.

  • CVE-2022-28173CriDec 19, 2022
    risk 0.59cvss 9.1epss 0.01

    The web server of some Hikvision wireless bridge products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.

  • CVE-2022-4063CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.10

    The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.

  • CVE-2022-4050CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.05

    The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

  • CVE-2022-44755CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…

  • CVE-2022-44754CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…

  • CVE-2022-44753CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file.  This vulnerability applies to…

  • CVE-2022-44752CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file.  This vulnerability applies to…

  • CVE-2022-44751CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…

  • CVE-2022-44750CriDec 19, 2022
    risk 0.64cvss 9.8epss 0.01

    HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the…

  • CVE-2022-44456CriDec 19, 2022
    risk 0.69cvss 9.8epss 0.70

    CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request.

  • CVE-2022-4606CriDec 18, 2022
    risk 0.03cvss 9.8epss 0.35

    PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3.