Latest CVE Feed
-
5.5
MEDIUMCVE-2022-1354
A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a ... Read more
Affected Products : enterprise_linux fedora debian_linux ontap_select_deploy_administration_utility libtiff- Published: Aug. 31, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-1198
A use-after-free vulnerabilitity was discovered in drivers/net/hamradio/6pack.c of linux that allows an attacker to crash linux kernel by simulating ax25 device using 6pack driver from user space.... Read more
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-1184
A use-after-free flaw was found in fs/ext4/namei.c:dx_insert_block() in the Linux kernel’s filesystem sub-component. This flaw allows a local attacker with a user privilege to cause a denial of service.... Read more
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-1122
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized... Read more
- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-35101
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via /multiarch/memset-vec-unaligned-erms.S.... Read more
Affected Products : swftools- Published: Aug. 16, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-1115
A heap-buffer-overflow flaw was found in ImageMagick’s PushShortPixel() function of quantum-private.h file. This vulnerability is triggered when an attacker passes a specially crafted TIFF image file to ImageMagick for conversion, potentially leading to a... Read more
Affected Products : imagemagick- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-1016
A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle 'return' with proper preconditions, as it can lead to a kernel information leak problem caused by a local, un... Read more
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0907
Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f2b656e2.... Read more
- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0882
A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX_RSRC_KIND_ROOT. It is recommended to upgrade the Fuchsia kernel to 4.1.1 or greater.... Read more
Affected Products : fuchsia- Published: May. 03, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0837
The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing any customer to send paid test SMS notification as well as retrieve sensitive information about the admin, such as the email, account b... Read more
Affected Products : amelia- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0825
The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's booking status, as well as retrieve sensitive information about the bookings, such as the full name and phone ... Read more
Affected Products : amelia- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0854
A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to read random memory from the kernel space.... Read more
- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0851
There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the act... Read more
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0720
The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any customer to update other's booking, as well as retrieve sensitive information about the bookings, such as the full name and phone number ... Read more
Affected Products : amelia- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0727
Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.... Read more
Affected Products : peertube- Published: Feb. 23, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0632
NULL Pointer Dereference in Homebrew mruby prior to 3.2.... Read more
Affected Products : mruby- Published: Feb. 19, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0563
A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prin... Read more
- Published: Feb. 21, 2022
- Modified: Jun. 09, 2025
-
5.5
MEDIUMCVE-2022-0544
An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read sensitive data using a crafted DDS image file. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.... Read more
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0561
Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, the fi... Read more
Affected Products : enterprise_linux fedora debian_linux ontap_select_deploy_administration_utility libtiff- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-0562
Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, a fix is a... Read more
- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024