Search

Found 5,521 results in 2387ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-49156 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix scheduling while atomic The driver makes a call into midlayer (fc_remote_port_delete) which can put the thread…
CVE-2022-49153 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: wireguard: socket: free skb in send6 when ipv6 is disabled I got a memory leak report: unreferenced object 0xffff8881191fc040 (s…
CVE-2022-49152 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: XArray: Fix xas_create_range() when multi-order entry present If there is already an entry present that is of order >= XA_CHUNK_S…
CVE-2022-49147 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: block: Fix the maximum minor value is blk_alloc_ext_minor() ida_alloc_range(..., min, max, ...) returns values from min to max, i…
CVE-2022-49145 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ACPI: CPPC: Avoid out of bounds access when parsing _CPC data If the NumEntries field in the _CPC return package is less than 2, …
CVE-2022-49142 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: net: preserve skb_end_offset() in skb_unclone_keeptruesize() syzbot found another way to trigger the infamous WARN_ON_ONCE(delta …
CVE-2022-49130 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ath11k: mhi: use mhi_sync_power_up() If amss.bin was missing ath11k would crash during 'rmmod ath11k_pci'. The reason for that wa…
CVE-2022-49129 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: mt76: mt7921: fix crash when startup fails. If the nic fails to start, it is possible that the reset_work has already been schedu…
CVE-2022-49123 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ath11k: Fix frames flush failure caused by deadlock We are seeing below warnings: kernel: [25393.301506] ath11k_pci 0000:01:00.0…
CVE-2022-49122 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: dm ioctl: prevent potential spectre v1 gadget It appears like cmd could be a Spectre v1 gadget as it's supplied by a user and use…
CVE-2022-49109 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ceph: fix inode reference leakage in ceph_get_snapdir() The ceph_get_inode() will search for or insert a new inode into the hash …
CVE-2022-49107 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ceph: fix memory leak in ceph_readdir when note_last_dentry returns error Reset the last_readdir at the same time, and add a comm…
CVE-2022-49098 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Fix potential crash on module unload The vmbus driver relies on the panic notifier infrastructure to perform …
CVE-2022-49093 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: skbuff: fix coalescing for page_pool fragment recycling Fix a use-after-free when using page_pool with page fragments. We encount…
CVE-2022-49090 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: arch/arm64: Fix topology initialization for core scheduling Arm64 systems rely on store_cpu_topology() to call update_siblings_ma…
CVE-2022-49086 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix leak of nested actions While parsing user-provided actions, openvswitch module may dynamically allocate mem…
CVE-2022-49066 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: veth: Ensure eth header is in skb's linear part After feeding a decapsulated packet to a veth device with act_mirred, skb_headlen…
CVE-2022-49060 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: net/smc: Fix NULL pointer dereference in smc_pnet_find_ib() dev_name() was called with dev.parent as argument but without to NULL…
CVE-2022-48936 medium 5.5 rhel rocky sles 4y ago RHSA-2024:8870: kernel-rt security update (Moderate)
CVE-2022-48921 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix fault in reweight_entity Syzbot found a GPF in reweight_entity. This has been bisected to commit 4ef0c5c6b5ba ("k…
CVE-2022-48918 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: iwlwifi: mvm: check debugfs_dir ptr before use When "debugfs=off" is used on the kernel command line, iwiwifi's mvm module uses a…
CVE-2022-48912 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: netfilter: fix use-after-free in __nf_register_net_hook() We must not dereference @new_hooks after nf_hook_mutex has been release…
CVE-2022-48905 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ibmvnic: free reset-work-item when flushing Fix a tiny memory leak when flushing the reset work queue.
CVE-2022-48786 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: vsock: remove vsock from connected table when connect is interrupted by a signal vsock_connect() expects that the socket could al…
CVE-2022-48765 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: KVM: LAPIC: Also cancel preemption timer during SET_LAPIC The below warning is splatting during guest reboot. ------------[ cu…
CVE-2022-48738 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Reject out of bounds values in snd_soc_put_volsw() We don't currently validate that the values being set are within th…
CVE-2022-48735 medium 5.5 FIX rhel slesdebian debian 4y ago In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: Fix UAF of leds class devs at unbinding The LED class devices that are created by HD-audio codec drivers are registere…
CVE-2022-42432 medium 5.5 FIX rhel slesdebian debian 4y ago This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel 6.0-rc2. An attacker must first obtain the ability to execute high-privileged…
CVE-2022-39190 medium 5.5 FIX rhelalmalinux almalinux sles 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-36946 medium 5.5 FIX arch arch rhelalmalinux almalinux 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-3500 medium 5.5 FIX rhel sles rocky 4y ago Moderate: keylime security update
CVE-2022-32990 medium 5.5 FIX rhel slesdebian debian 4y ago Moderate: gimp security and enhancement update
CVE-2022-32891 medium 5.5 FIX arch arch rhel sles 4y ago The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.
CVE-2022-32816 medium 5.5 FIX arch arch rhel sles 4y ago The issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Visiting a website that frames malicious content may l…
CVE-2022-32792 medium 5.5 FIX arch arch rhel sles 4y ago An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing malici…
CVE-2022-32746 medium 5.5 FIX rhelarch arch rocky 4y ago RHSA-2022:7730: libldb security, bug fix, and enhancement update (Moderate)
CVE-2022-32742 medium 5.5 FIX rhelarch arch sles 4y ago RHSA-2022:7111: samba security and bug fix update (Moderate)
CVE-2022-32189 medium 5.5 FIX rocky rhel sles 4y ago RHSA-2023:2802: container-tools:4.0 security and bug fix update (Moderate)
CVE-2022-31813 medium 5.5 FIX debian debian rhelarch arch 4y ago Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based auth…
CVE-2022-31625 medium 5.5 FIX arch arch rhel rocky 4y ago RHSA-2022:7624: php:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-3107 medium 5.5 FIX rhel slesdebian debian 4y ago An issue was discovered in the Linux kernel through 5.16-rc6. netvsc_get_ethtool_stats in drivers/net/hyperv/netvsc_drv.c lacks check of the return value of kvmalloc_array() and will cause the null p…
CVE-2022-30699 medium 5.5 FIX rhel rocky sles 4y ago RHSA-2022:7622: unbound security, bug fix, and enhancement update (Moderate)
CVE-2022-30698 medium 5.5 FIX rhel rocky sles 4y ago RHSA-2022:7622: unbound security, bug fix, and enhancement update (Moderate)
CVE-2022-30556 medium 5.5 FIX debian debian rhelarch arch 4y ago Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.
CVE-2022-30550 medium 5.5 FIX arch arch rheldebian debian 4y ago An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and m…
CVE-2022-30522 medium 5.5 FIX debian debian rhelarch arch 4y ago If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigg…
CVE-2022-30293 medium 5.5 FIX rhelarch arch rocky 4y ago In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.
CVE-2022-30067 medium 5.5 FIX rhel slesdebian debian 4y ago Moderate: gimp security and enhancement update
CVE-2022-29901 medium 5.5 FIX rhelalmalinux almalinux sles 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-29900 medium 5.5 FIX rhelalmalinux almalinux sles 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-2990 low 2.5 FIX rhel rocky sles 4y ago RHSA-2022:7822: container-tools:rhel8 security, bug fix, and enhancement update (Low)
CVE-2022-2989 medium 5.5 FIX rocky rhel sles 4y ago RHSA-2023:2802: container-tools:4.0 security and bug fix update (Moderate)
CVE-2022-29581 medium 5.5 FIX rhelalmalinux almalinux rocky 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-29404 medium 5.5 FIX debian debian rhelarch arch 4y ago In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size.
CVE-2022-29162 medium 5.5 FIX rhelarch arch sles 4y ago RHSA-2022:7469: container-tools:4.0 security and bug fix update (Moderate)
CVE-2022-28893 medium 5.5 FIX rhelalmalinux almalinux rocky 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-28615 medium 5.5 FIX debian debian rhelarch arch 4y ago Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed …
CVE-2022-28614 medium 5.5 FIX debian debian rhelarch arch 4y ago The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as w…
CVE-2022-2850 medium 5.5 FIX debian debian rhel sles 4y ago RHSA-2022:7133: 389-ds:1.4 security update (Moderate)
CVE-2022-28390 medium 5.5 FIX rhelalmalinux almalinuxarch arch 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-27406 medium 5.5 FIX rhel rocky sles 4y ago RHSA-2022:7745: freetype security update (Moderate)
CVE-2022-27405 medium 5.5 FIX rhel rocky sles 4y ago RHSA-2022:7745: freetype security update (Moderate)
CVE-2022-27404 medium 5.5 FIX rhel rocky sles 4y ago RHSA-2022:7745: freetype security update (Moderate)
CVE-2022-27191 medium 5.5 FIX rhelalmalinux almalinux sles 4y ago RHSA-2022:7469: container-tools:4.0 security and bug fix update (Moderate)
CVE-2022-26719 medium 5.5 FIX rhelarch arch rocky 4y ago A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing malicious…
CVE-2022-26717 medium 5.5 FIX rhelarch arch rocky 4y ago A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5, iTunes 12.12.4 for Win…
CVE-2022-26716 medium 5.5 FIX rhelarch arch rocky 4y ago A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing malicious…
CVE-2022-26710 medium 5.5 FIX arch arch rhel rocky 4y ago A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, tvOS 15.5, watchOS 8.6. Processing maliciously crafted web …
CVE-2022-26709 medium 5.5 FIX rhelarch arch rocky 4y ago A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing maliciously…
CVE-2022-26700 medium 5.5 FIX rhelarch arch rocky 4y ago A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5. Processing malicious…
CVE-2022-2639 medium 5.5 FIX rhelalmalinux almalinux rocky 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-26377 medium 5.5 FIX debian debian rhelarch arch 4y ago Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards reque…
CVE-2022-26373 medium 5.5 FIX almalinux almalinux rhel rocky 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-26125 medium 5.5 FIX rhel slesdebian debian 4y ago Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.
CVE-2022-2586 medium 7.0 KEVFIX rhelalmalinux almalinux rocky 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-25310 medium 5.5 FIX rhel sles rocky 4y ago RHSA-2022:7514: fribidi security update (Moderate)
CVE-2022-25309 medium 5.5 FIX rhel sles rocky 4y ago RHSA-2022:7514: fribidi security update (Moderate)
CVE-2022-25308 medium 5.5 FIX rhel sles rocky 4y ago RHSA-2022:7514: fribidi security update (Moderate)
CVE-2022-25255 medium 5.5 FIX rhel sles rocky 4y ago In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.
CVE-2022-2503 medium 5.5 FIX arch arch rhel sles 4y ago Dm-verity is used for extending root-of-trust to root filesystems. LoadPin builds on this property to restrict module/firmware loads to just the trusted root filesystem. Device-mapper table reloads c…
CVE-2022-24736 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7541: redis:6 security, bug fix, and enhancement update (Low)
CVE-2022-24735 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7541: redis:6 security, bug fix, and enhancement update (Low)
CVE-2022-24448 medium 5.5 FIX rhelalmalinux almalinux rocky 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-23943 medium 5.5 FIX debian debian rhel sles 4y ago Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version …
CVE-2022-23825 medium 5.5 FIX rhelalmalinux almalinux sles 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-23816 medium 5.5 FIX rhelalmalinux almalinux sles 4y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2022-23645 low 2.5 FIX rhel rockydebian debian 4y ago RHSA-2022:7472: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Low)
CVE-2022-2320 medium 5.5 FIX rhelarch arch sles 4y ago A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, whi…
CVE-2022-2319 medium 5.5 FIX rhelarch arch sles 4y ago A flaw was found in the Xorg-x11-server. An out-of-bounds access issue can occur in the ProcXkbSetGeometry function due to improper validation of the request length.
CVE-2022-2309 medium 5.5 FIX rhel slesdebian debian 4y ago NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earli…
CVE-2022-22844 medium 5.5 FIX rhelarch arch rocky 4y ago RHSA-2022:7585: libtiff security update (Moderate)
CVE-2022-22721 medium 5.5 FIX debian debian rhel rocky 4y ago If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apac…
CVE-2022-22719 medium 5.5 FIX debian debian rhel sles 4y ago A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.
CVE-2022-22662 medium 5.5 FIX arch arch rhel rocky 4y ago A cookie management issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5. Processing maliciously crafted web content may …
CVE-2022-22629 medium 5.5 FIX rhel rocky sles 4y ago A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iTunes 12.12.3 for Windows, iOS 15.4 and iPadOS 15.4, tvOS 1…
CVE-2022-22628 medium 5.5 FIX rhel rocky sles 4y ago A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously…
CVE-2022-22624 medium 5.5 FIX rhel rocky sles 4y ago A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3, iOS 15.4 and iPadOS 15.4, tvOS 15.4, Safari 15.4. Processing maliciously crafted web …
CVE-2022-2211 low 2.5 FIX rhel sles rocky 4y ago RHSA-2022:7472: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Low)
CVE-2022-21713 medium 5.5 rhel sles rocky 4y ago RHSA-2022:7519: grafana security, bug fix, and enhancement update (Moderate)
CVE-2022-21703 medium 5.5 rhel sles rocky 4y ago RHSA-2022:7519: grafana security, bug fix, and enhancement update (Moderate)