Latest CVE Feed
-
3.3
LOWCVE-2022-22598
An issue with app access to camera metadata was addressed with improved logic. This issue is fixed in iOS 15.4 and iPadOS 15.4. An app may be able to learn information about the current camera view before being granted camera access.... Read more
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-22597
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. Processing a maliciously crafted file may lead to arbitrary code execution.... Read more
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-22596
A memory corruption issue was addressed with improved validation. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4. An application may be able to execute arbitrary code with kernel privileges.... Read more
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-22594
A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.... Read more
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2022-22593
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. A malicious application may be able... Read more
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-22592
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may prevent Content Security Policy from bein... Read more
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2022-22591
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges.... Read more
Affected Products : macos- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-22590
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may lead to arbitrary code executio... Read more
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-22589
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing a maliciously crafted mail message may lead to running arbitrary javas... Read more
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-22588
A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 15.2.1 and iPadOS 15.2.1. Processing a maliciously crafted HomeKit accessory name may cause a denial of service.... Read more
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2022-22586
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges.... Read more
Affected Products : macos- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-22585
An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, macOS Monterey 12.2, macOS Big Sur 11.6.3. An application ma... Read more
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2022-22584
A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.3, iOS 15.3 and iPadOS 15.3, watchOS 8.4, macOS Monterey 12.2. Processing a maliciously crafted file may lead to arbitrary code execution.... Read more
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-22583
A permissions issue was addressed with improved validation. This issue is fixed in Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. An application may be able to access restricted files.... Read more
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-22582
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5, macOS Monterey 12.3. A local user may be able to write a... Read more
- Published: Feb. 27, 2023
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2022-22579
An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, tvOS 15.3, Security Update 2022-001 Catalina, macOS Monterey 12.2, macOS Big Sur 11.6.3. Processing a maliciously crafted STL fi... Read more
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2022-22578
A logic issue was addressed with improved validation. This issue is fixed in tvOS 15.3, iOS 15.3 and iPadOS 15.3, watchOS 8.4, macOS Monterey 12.2. A malicious application may be able to gain root privileges.... Read more
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-22577
An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.... Read more
- Published: May. 26, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2022-22576
An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this tr... Read more
Affected Products : debian_linux curl solidfire_\&_hci_management_node h300s_firmware h500s_firmware h700s_firmware h410s_firmware clustered_data_ontap solidfire_\&_hci_storage_node universal_forwarder +7 more products- Published: May. 26, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-22572
A non-admin user with user management permission can escalate his privilege to admin user via password reset functionality. The vulnerability affects Incapptic Connect version < 1.40.1.... Read more
Affected Products : incapptic_connect- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024