57.971 CVE seguite
788 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordinato dal più basso |
|---|---|---|---|---|
| CVE-2022-0854 | MED 5.5 | debian debian_linux A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to read random memory from the kernel space. | 0,5% | — |
| CVE-2022-0850 | HIGH 7.1 | linux linux_kernel A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace. | 0,4% | — |
| CVE-2022-0812 | MED 4.3 | linux linux_kernel An information leak flaw was found in NFS over RDMA in the net/sunrpc/xprtrdma/rpc_rdma.c in the Linux Kernel. This flaw allows an attacker with normal user privileges to leak kernel information. | 1,4% | — |
| CVE-2022-0807 | MED 6.5 | google chrome Inappropriate implementation in Autofill in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | 0,9% | — |
| CVE-2022-0806 | MED 6.5 | google chrome Data leak in Canvas in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in screen sharing to potentially leak cross-origin data via a crafted HTML page. | 1,0% | — |
| CVE-2022-0805 | HIGH 8.8 | google chrome Use after free in Browser Switcher in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction. | 0,9% | — |
| CVE-2022-0804 | MED 6.5 | google chrome Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. | 0,9% | — |
| CVE-2022-0803 | MED 6.5 | google chrome Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to tamper with the contents of the Omnibox (URL bar) via a crafted HTML page. | 0,9% | — |
| CVE-2022-0802 | MED 6.5 | google chrome Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. | 0,9% | — |
| CVE-2022-0799 | HIGH 8.8 | google chrome Insufficient policy enforcement in Installer in Google Chrome on Windows prior to 99.0.4844.51 allowed a remote attacker to perform local privilege escalation via a crafted offline installer file. | 1,0% | — |
| CVE-2022-0798 | HIGH 8.8 | google chrome Use after free in MediaStream in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. | 0,7% | — |
| CVE-2022-0797 | HIGH 8.8 | google chrome Out of bounds memory access in Mojo in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. | 1,7% | — |
| CVE-2022-0796 | HIGH 8.8 | google chrome Use after free in Media in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 1,0% | — |
| CVE-2022-0791 | HIGH 8.8 | google chrome Use after free in Omnibox in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via user interactions. | 0,9% | — |
| CVE-2022-0742 | CRIT 9.1 | linux linux_kernel Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend upgrading past commit 2d3916f3189172d5c69d33065c3c21119fe539fc. | 5,0% | — |
| CVE-2022-0646 | HIGH 7.8 | linux linux_kernel A flaw use after free in the Linux kernel Management Component Transport Protocol (MCTP) subsystem was found in the way user triggers cancel_work_sync after the unregister_netdev during removing device. A local user could use this flaw to crash the system or e | 0,3% | — |
| CVE-2022-0617 | MED 5.5 | debian debian_linux A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc | 0,5% | — |
| CVE-2022-0564 | MED 5.3 | qlik qlik_sense A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A successful exploit could allow the at | 1,4% | — |
| CVE-2022-0516 | HIGH 7.8 | debian debian_linux A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized memory write access. This flaw affects Linux | 0,3% | — |
| CVE-2022-0500 | HIGH 7.8 | fedoraproject fedora A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to crash or escalate their privileges on the sy | 0,4% | — |
| CVE-2022-0494 | MED 4.4 | debian debian_linux A kernel information leak flaw was identified in the scsi_ioctl function in drivers/scsi/scsi_ioctl.c in the Linux kernel. This flaw allows a local attacker with a special user privilege (CAP_SYS_ADMIN or CAP_SYS_RAWIO) to create issues with confidentiality. | 0,4% | — |
| CVE-2022-0487 | MED 5.5 | debian debian_linux A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidentiality. This flaw affects kernel versions | 0,4% | — |
| CVE-2022-0483 | HIGH 7.8 | acronis vss_doctor Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53 | 0,2% | — |
| CVE-2022-0480 | MED 5.5 | linux linux_kernel A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can lead to host memory exhaustion due to memcg not limiting the number of Portable Operating System Interface (POSIX) file locks. | 0,3% | — |
| CVE-2022-0435 | HIGH 8.8 | fedoraproject fedora A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system | 68,0% | — |