58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2022-1016 | MED 5.5 | linux linux_kernel A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle 'return' with proper preconditions, as it can lead to a kernel information leak problem caused by a local, unprivi | 0.4% | — |
| CVE-2022-1015 | MED 6.6 | fedoraproject fedora A flaw was found in the Linux kernel in linux/net/netfilter/nf_tables_api.c of the netfilter subsystem. This flaw allows a local user to cause an out-of-bounds write issue. | 1.5% | — |
| CVE-2022-1012 | HIGH 8.2 | linux linux_kernel A memory leak problem was found in the TCP source port generation algorithm in net/ipv4/tcp.c due to the small table perturb size. This flaw may allow an attacker to information leak and may cause a denial of service problem. | 3.9% | — |
| CVE-2022-1011 | HIGH 7.8 | debian debian_linux A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation. | 1.2% | — |
| CVE-2022-0998 | HIGH 7.8 | linux linux_kernel An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_vdpa_config_validate function. This flaw allows a local user to crash or potentially escalate their privileges on the system. | 0.4% | — |
| CVE-2022-0972 | HIGH 8.8 | google chrome Use after free in Extensions in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. | 0.8% | — |
| CVE-2022-0971 | HIGH 8.8 | google chrome Use after free in Blink Layout in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | 1.2% | — |
| CVE-2022-0883 | HIGH 7.3 | snowsoftware snow_license_manager SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched. | 0.2% | — |
| CVE-2022-0854 | MED 5.5 | debian debian_linux A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to read random memory from the kernel space. | 0.5% | — |
| CVE-2022-0850 | HIGH 7.1 | linux linux_kernel A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace. | 0.4% | — |
| CVE-2022-0812 | MED 4.3 | linux linux_kernel An information leak flaw was found in NFS over RDMA in the net/sunrpc/xprtrdma/rpc_rdma.c in the Linux Kernel. This flaw allows an attacker with normal user privileges to leak kernel information. | 1.4% | — |
| CVE-2022-0807 | MED 6.5 | google chrome Inappropriate implementation in Autofill in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | 0.9% | — |
| CVE-2022-0806 | MED 6.5 | google chrome Data leak in Canvas in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in screen sharing to potentially leak cross-origin data via a crafted HTML page. | 1.0% | — |
| CVE-2022-0805 | HIGH 8.8 | google chrome Use after free in Browser Switcher in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction. | 0.9% | — |
| CVE-2022-0804 | MED 6.5 | google chrome Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. | 0.9% | — |
| CVE-2022-0803 | MED 6.5 | google chrome Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to tamper with the contents of the Omnibox (URL bar) via a crafted HTML page. | 0.9% | — |
| CVE-2022-0802 | MED 6.5 | google chrome Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. | 0.9% | — |
| CVE-2022-0799 | HIGH 8.8 | google chrome Insufficient policy enforcement in Installer in Google Chrome on Windows prior to 99.0.4844.51 allowed a remote attacker to perform local privilege escalation via a crafted offline installer file. | 1.0% | — |
| CVE-2022-0798 | HIGH 8.8 | google chrome Use after free in MediaStream in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. | 0.7% | — |
| CVE-2022-0797 | HIGH 8.8 | google chrome Out of bounds memory access in Mojo in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. | 1.7% | — |
| CVE-2022-0796 | HIGH 8.8 | google chrome Use after free in Media in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 1.0% | — |
| CVE-2022-0791 | HIGH 8.8 | google chrome Use after free in Omnibox in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via user interactions. | 0.9% | — |
| CVE-2022-0742 | CRIT 9.1 | linux linux_kernel Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend upgrading past commit 2d3916f3189172d5c69d33065c3c21119fe539fc. | 5.0% | — |
| CVE-2022-0646 | HIGH 7.8 | linux linux_kernel A flaw use after free in the Linux kernel Management Component Transport Protocol (MCTP) subsystem was found in the way user triggers cancel_work_sync after the unregister_netdev during removing device. A local user could use this flaw to crash the system or e | 0.4% | — |
| CVE-2022-0617 | MED 5.5 | debian debian_linux A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc | 0.5% | — |