VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2022-3635MedOct 21, 2022
    risk 0.00cvss 5.5epss 0.00

    A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this issue is the function tst_timer of the file drivers/atm/idt77252.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this…

  • CVE-2022-3633LowOct 21, 2022
    risk 0.00cvss 3.5epss 0.00

    A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function j1939_session_destroy of the file net/can/j1939/transport.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this…

  • CVE-2022-3629LowOct 21, 2022
    risk 0.00cvss 2.6epss 0.00

    A vulnerability was found in Linux Kernel. It has been declared as problematic. This vulnerability affects the function vsock_connect of the file net/vmw_vsock/af_vsock.c. The manipulation leads to memory leak. The complexity of an attack is rather high. The exploitation appears…

  • CVE-2022-3625MedOct 21, 2022
    risk 0.00cvss 4.6epss 0.00

    A vulnerability was found in Linux Kernel. It has been classified as critical. This affects the function devlink_param_set/devlink_param_get of the file net/core/devlink.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix…

  • CVE-2022-3623MedOct 20, 2022
    risk 0.00cvss 5.0epss 0.01

    A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function follow_page_pte of the file mm/gup.c of the component BPF. The manipulation leads to race condition. The attack can be launched remotely. It is…

  • CVE-2022-3621MedOct 20, 2022
    risk 0.00cvss 4.3epss 0.01

    A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_bmap_lookup_at_level of the file fs/nilfs2/inode.c of the component nilfs2. The manipulation leads to null pointer dereference. It is possible to launch the attack…

  • CVE-2022-3586MedOct 19, 2022
    risk 0.00cvss 5.5epss 0.00

    A flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue function used the socket buffer (SKB) cb field after the same SKB had been enqueued (and freed) into a child qdisc. This flaw allows a local, unprivileged user to…

  • CVE-2022-3594MedOct 18, 2022
    risk 0.00cvss 5.3epss 0.02

    A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function intr_callback of the file drivers/net/usb/r8152.c of the component BPF. The manipulation leads to logging of excessive data. The attack can be launched…

  • CVE-2022-3564MedOct 17, 2022
    risk 0.00cvss 5.5epss 0.01

    A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch…

  • CVE-2022-41751HigOct 17, 2022
    risk 0.00cvss 7.8epss 0.00

    Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.

  • CVE-2022-3551LowOct 17, 2022
    risk 0.00cvss 3.5epss 0.02

    A vulnerability, which was classified as problematic, has been found in X.org Server. Affected by this issue is the function ProcXkbGetKbdByName of the file xkb/xkb.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of…

  • CVE-2022-3550MedOct 17, 2022
    risk 0.00cvss 5.5epss 0.02

    A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of…

  • CVE-2022-3545MedOct 17, 2022
    risk 0.00cvss 5.5epss 0.00

    A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerability is the function area_cache_get of the file drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c of the component IPsec. The manipulation leads to use after free. It is…

  • CVE-2022-3524MedOct 16, 2022
    risk 0.00cvss 4.3epss 0.01

    A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function ipv6_renew_options of the component IPv6 Handler. The manipulation leads to memory leak. The attack can be launched remotely. It is recommended to apply…

  • CVE-2022-3521LowOct 16, 2022
    risk 0.00cvss 2.6epss 0.00

    A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function kcm_tx_work of the file net/kcm/kcmsock.c of the component kcm. The manipulation leads to race condition. It is recommended to apply a patch to fix this issue.…

  • CVE-2022-42722MedOct 14, 2022
    risk 0.00cvss 5.5epss 0.01

    In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames into the mac80211 stack could cause a NULL pointer dereference denial-of-service attack against the beacon protection of P2P devices.

  • CVE-2022-42721MedOct 14, 2022
    risk 0.00cvss 5.5epss 0.01

    A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked list and, in turn, potentially execute code.

  • CVE-2022-42720HigOct 14, 2022
    risk 0.00cvss 7.8epss 0.01

    Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger use-after-free conditions to potentially execute code.

  • CVE-2022-41674HigOct 14, 2022
    risk 0.00cvss 8.1epss 0.04

    An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c.

  • CVE-2022-42719HigOct 13, 2022
    risk 0.00cvss 8.8epss 0.01

    A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before 5.19.16 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code.

  • CVE-2021-36369HigOct 12, 2022
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code, it is possible for an SSH server to change the login process in its favor. This attack can bypass additional security…

  • CVE-2022-41850MedSep 30, 2022
    risk 0.00cvss 4.7epss 0.00

    roccat_report_event in drivers/hid/hid-roccat.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free in certain situations where a report is received while copying a report->value is in progress.

  • CVE-2022-41849MedSep 30, 2022
    risk 0.00cvss 4.2epss 0.00

    drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a USB device while calling open(), aka a race condition between ufx_ops_open and ufx_usb_disconnect.

  • CVE-2022-3352HigSep 29, 2022
    risk 0.00cvss 7.8epss 0.00

    Use After Free in GitHub repository vim/vim prior to 9.0.0614.

  • CVE-2022-32166MedSep 28, 2022
    risk 0.00cvss 6.1epss 0.01

    In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification, and possible…

  • CVE-2022-3324HigSep 27, 2022
    risk 0.00cvss 7.8epss 0.01

    Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.

  • CVE-2022-3303MedSep 27, 2022
    risk 0.00cvss 4.7epss 0.00

    A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL pointer dereference while handling the SNDCTL_DSP_SYNC ioctl. A privileged local user (root or member of the audio group) could use this flaw to crash the system,…

  • CVE-2022-3256HigSep 22, 2022
    risk 0.00cvss 7.8epss 0.00

    Use After Free in GitHub repository vim/vim prior to 9.0.0530.

  • CVE-2022-41222HigSep 21, 2022
    risk 0.00cvss 7.0epss 0.00

    mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move.

  • CVE-2022-41218MedSep 21, 2022
    risk 0.00cvss 5.5epss 0.01

    In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release.

  • CVE-2022-37032CriSep 19, 2022
    risk 0.00cvss 9.1epss 0.02

    An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.

  • CVE-2022-3235HigSep 18, 2022
    risk 0.00cvss 7.8epss 0.00

    Use After Free in GitHub repository vim/vim prior to 9.0.0490.

  • CVE-2022-40768MedSep 18, 2022
    risk 0.00cvss 5.5epss 0.00

    drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case.

  • CVE-2022-3234HigSep 17, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.

  • CVE-2022-3176HigSep 16, 2022
    risk 0.00cvss 7.8epss 0.00

    There exists a use-after-free in io_uring in the Linux kernel. Signalfd_poll() and binder_poll() use a waitqueue whose lifetime is the current task. It will send a POLLFREE notification to all waiters before the queue is freed. Unfortunately, the io_uring poll doesn't handle…

  • CVE-2022-40674HigSep 14, 2022
    risk 0.00cvss 8.1epss 0.02

    libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

  • CVE-2022-38266MedSep 9, 2022
    risk 0.00cvss 6.5epss 0.01

    An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.

  • CVE-2022-40307MedSep 9, 2022
    risk 0.00cvss 4.7epss 0.00

    An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition with a resultant use-after-free.

  • CVE-2022-3134HigSep 6, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.0389.

  • CVE-2022-3008HigSep 5, 2022
    risk 0.00cvss 8.1epss 0.03

    The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. This function allows for command injection by using backticks. An attacker could craft an untrusted path input that would result in…

  • CVE-2022-39842MedSep 5, 2022
    risk 0.00cvss 6.1epss 0.01

    An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer overflow and bypassing the size check. After that, because it is used as the third…

  • CVE-2022-3099HigSep 3, 2022
    risk 0.00cvss 7.8epss 0.00

    Use After Free in GitHub repository vim/vim prior to 9.0.0360.

  • CVE-2020-29260HigSep 2, 2022
    risk 0.00cvss 7.5epss 0.01

    libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup().

  • CVE-2020-22669CriSep 2, 2022
    risk 0.00cvss 9.8epss 0.01

    Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web…

  • CVE-2022-39190MedSep 2, 2022
    risk 0.00cvss 5.5epss 0.00

    An issue was discovered in net/netfilter/nf_tables_api.c in the Linux kernel before 5.19.6. A denial of service can occur upon binding to an already bound chain.

  • CVE-2022-39188MedSep 2, 2022
    risk 0.00cvss 4.7epss 0.00

    An issue was discovered in include/asm-generic/tlb.h in the Linux kernel before 5.19. Because of a race condition (unmap_mapping_range versus munmap), a device driver can free a page while it still has stale TLB entries. This only occurs in situations with VM_PFNMAP VMAs.

  • CVE-2022-3061MedSep 1, 2022
    risk 0.00cvss 5.5epss 0.00

    Found Linux Kernel flaw in the i740 driver. The Userspace program could pass any values to the driver through ioctl() interface. The driver doesn't check the value of 'pixclock', so it may cause a divide by zero error.

  • CVE-2020-35533MedSep 1, 2022
    risk 0.00cvss 5.5epss 0.00

    In LibRaw, an out-of-bounds read vulnerability exists within the "LibRaw::adobe_copy_pixel()" function (libraw\src\decoders\dng.cpp) when reading data from the image file.

  • CVE-2020-35532MedSep 1, 2022
    risk 0.00cvss 5.5epss 0.00

    In LibRaw, an out-of-bounds read vulnerability exists within the "simple_decode_row()" function (libraw\src\x3f\x3f_utils_patched.cpp) which can be triggered via an image with a large row_stride field.

  • CVE-2020-35531MedSep 1, 2022
    risk 0.00cvss 5.5epss 0.00

    In LibRaw, an out-of-bounds read vulnerability exists within the get_huffman_diff() function (libraw\src\x3f\x3f_utils_patched.cpp) when reading data from an image file.

Page 172 of 210