CVEs from 2022

5,236 normalized CVEs published or assigned in this year.

Total
5,236
critical
critical 92
high
high 1,236
medium
medium 953
low
low 24
% Critical
1.8%
% with KEV
2.5%
% with exploit
3.4%

Top products

  • jdk 116
  • jre 109
  • openjdk 100
  • zulu 82
  • graalvm 74
  • cloud_secure_agent 35
  • oncommand_insight 34
  • cloud_insights_acquisition_unit 34
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-50625 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: serial: amba-pl011: avoid SBSA UART accessing DMACR register Chapter "B Generic UART" in "ARM Server Base System Architecture" [1…
CVE-2022-50761 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: x86/xen: Fix memory leak in xen_init_lock_cpu() In xen_init_lock_cpu(), the @name has allocated new string by kasprintf(), if bin…
CVE-2022-50177 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: rcutorture: Fix ksoftirqd boosting timing and iteration The RCU priority boosting can fail in two situations: 1) If (nr_cpus= > …
CVE-2022-49197 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: af_netlink: Fix shift out of bounds in group mask calculation When a netlink message is received, netlink_recvmsg() fills in the …
CVE-2022-49308 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: extcon: Modify extcon device to be created after driver data is set Currently, someone can invoke the sysfs such as state_show() …
CVE-2022-48669 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries: Fix potential memleak in papr_get_attr() `buf` is allocated in papr_get_attr(), and krealloc() of `buf` could fa…
CVE-2022-48703 medium 5.5 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: thermal/int340x_thermal: handle data_vault when the value is ZERO_SIZE_PTR In some case, the GDDV returns a package with a buffer…
CVE-2022-48672 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: of: fdt: fix off-by-one error in unflatten_dt_nodes() Commit 78c44d910d3e ("drivers/of: Fix depth when unflattening devicetree") …
CVE-2022-49941 medium 5.5 2y ago RHSA-2024:9315: kernel security update (Moderate)
CVE-2022-49124 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: x86/mce: Work around an erratum on fast string copy instructions A rare kernel panic scenario can happen when the following condi…
CVE-2022-49329 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: vduse: Fix NULL pointer dereference on sysfs access The control device has no drvdata. So we will get a NULL pointer dereference …
CVE-2022-48773 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: xprtrdma: fix pointer derefs in error cases of rpcrdma_ep_create If there are failures then we must not leave the non-NULL pointe…
CVE-2022-24805 medium 5.5 2y ago Moderate: net-snmp security update
CVE-2022-24809 medium 5.5 2y ago Moderate: net-snmp security update
CVE-2022-24808 medium 5.5 2y ago Moderate: net-snmp security update
CVE-2022-24810 medium 5.5 2y ago Moderate: net-snmp security update
CVE-2022-24806 medium 5.5 2y ago Moderate: net-snmp security update
CVE-2022-24807 medium 5.5 2y ago Moderate: net-snmp security update
CVE-2022-48743 medium 5.5 2y ago Moderate: kernel security update
CVE-2022-48829 medium 5.5 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes iattr::ia_size is a loff_t, so these NFSv3 procedures must be caref…
CVE-2022-48828 medium 5.5 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix ia_size underflow iattr::ia_size is a loff_t, which is a signed 64-bit type. NFSv3 and NFSv4 both define file size as a…
CVE-2022-48622 medium 5.5 2y ago Moderate: gdk-pixbuf2 security update
CVE-2022-50274 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: media: dvbdev: adopts refcnt to avoid UAF dvb_unregister_device() is known that prone to use-after-free. That is, the cleanup fro…
CVE-2022-48565 medium 5.5 2y ago An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.
CVE-2022-0500 medium 5.5 2y ago A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows…
CVE-2022-23222 medium 5.5 2y ago kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.
CVE-2022-50116 medium 5.5 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: fix deadlock and link starvation in outgoing data path The current implementation queues up new control and user pack…
CVE-2022-50782 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: ext4: fix bug_on in __es_tree_search caused by bad quota inode We got a issue as fllows: ========================================…
CVE-2022-49977 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix NULL pointer dereference in is_ftrace_trampoline when ftrace is dead ftrace_startup does not remove ops from ftrace_o…
CVE-2022-40090 medium 5.5 2y ago Moderate: libtiff security update
CVE-2022-49940 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: add sanity check for gsm->receive in gsm_receive_buf() A null pointer dereference can happen when attempting to acces…
CVE-2022-33065 medium 5.5 2y ago Moderate: libsndfile security update
CVE-2022-38096 medium 5.5 5.5 2y ago Important: kernel security, bug fix, and enhancement update
CVE-2022-50485 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: ext4: add EXT4_IGET_BAD flag to prevent unexpected bad inode There are many places that will get unhappy (and crash) when ext4_ig…
CVE-2022-50286 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: ext4: fix delayed allocation bug in ext4_clu_mapped for bigalloc + inline When converting files with inline data to extents, dela…
CVE-2022-48947 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix u8 overflow By keep sending L2CAP_CONF_REQ packets, chan->num_conf_rsp increases multiple times and eventua…
CVE-2022-50638 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: ext4: fix bug_on in __es_tree_search caused by bad boot loader inode We got a issue as fllows: ==================================…
CVE-2022-50673 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: ext4: fix use-after-free in ext4_orphan_cleanup I caught a issue as follows: ====================================================…
CVE-2022-48560 medium 5.5 2y ago RHSA-2024:2987: python27:2.7 security update (Moderate)
CVE-2022-48564 medium 5.5 2y ago read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.
CVE-2022-44638 medium 5.5 3y ago RHSA-2024:0131: pixman security update (Moderate)
CVE-2022-24963 medium 5.5 3y ago Moderate: apr security update
CVE-2022-3565 medium 5.5 3y ago A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this issue is the function del_timer of the file drivers/isdn/mISDN/l1oip_core.c of the component Blueto…
CVE-2022-50543 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix mr->map double free rxe_mr_cleanup() which tries to free mr->map again will be called when rxe_mr_init_user() fails…
CVE-2022-50087 medium 5.5 3y ago Moderate: kernel security update
CVE-2022-38745 medium 5.5 3y ago Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.
CVE-2022-50042 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: net: genl: fix error path memory leak in policy dumping If construction of the array of policies fails when recording non-first p…
CVE-2022-50327 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: idle: Check acpi_fetch_acpi_dev() return value The return value of acpi_fetch_acpi_dev() could be NULL, which wo…
CVE-2022-50369 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Fix null-ptr-deref in vkms_release() A null-ptr-deref is triggered when it tries to destroy the workqueue in vkms->outp…
CVE-2022-40898 medium 5.5 3y ago Moderate: python-wheel security update
CVE-2022-50269 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Fix memory leak in vkms_init() A memory leak was reported after the vkms module install failed. unreferenced object 0x…
CVE-2022-50423 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: ACPICA: Fix use-after-free in acpi_ut_copy_ipackage_to_ipackage() There is an use-after-free reported by KASAN: BUG: KASAN: us…
CVE-2022-39307 medium 5.5 3y ago Moderate: grafana security and enhancement update
CVE-2022-39201 medium 5.5 3y ago Moderate: grafana security and enhancement update
CVE-2022-39306 medium 5.5 3y ago Moderate: grafana security and enhancement update
CVE-2022-31123 medium 5.5 3y ago Moderate: grafana security and enhancement update
CVE-2022-40318 medium 5.5 3y ago Moderate: frr security and bug fix update
CVE-2022-39324 medium 5.5 3y ago Moderate: grafana security and enhancement update
CVE-2022-2127 medium 5.5 3y ago RHSA-2023:7139: samba security, bug fix, and enhancement update (Moderate)
CVE-2022-23527 medium 5.5 3y ago RHSA-2023:6940: mod_auth_openidc:2.3 security and bug fix update (Moderate)
CVE-2022-43681 medium 5.5 3y ago Moderate: frr security and bug fix update
CVE-2022-40302 medium 5.5 3y ago Moderate: frr security and bug fix update
CVE-2022-37601 medium 5.5 3y ago RHSA-2023:6972: grafana security and enhancement update (Moderate)
CVE-2022-36440 medium 5.5 3y ago Moderate: frr security and bug fix update
CVE-2022-3064 medium 5.5 3y ago RHSA-2024:10784: rhc security update (Moderate)
CVE-2022-48468 medium 5.5 3y ago RHSA-2023:6944: protobuf-c security update (Moderate)
CVE-2022-23552 medium 5.5 3y ago Moderate: grafana security and enhancement update
CVE-2022-50472 medium 5.5 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: IB/mad: Don't call to function that might sleep while in atomic context Tracepoints are not allowed to sleep, as such the followi…
CVE-2022-50856 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: cifs: Fix xid leak in cifs_ses_add_channel() Before return, should free the xid, otherwise, the xid will be leaked.
CVE-2022-50110 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: watchdog: sp5100_tco: Fix a memory leak of EFCH MMIO resource Unlike release_mem_region(), a call to release_resource() does not …
CVE-2022-50865 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: tcp: fix a signed-integer-overflow bug in tcp_add_backlog() The type of sk_rcvbuf and sk_sndbuf in struct sock is int, and in tcp…
CVE-2022-49885 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: ACPI: APEI: Fix integer overflow in ghes_estatus_pool_init() Change num_ghes from int to unsigned int, preventing an overflow and…
CVE-2022-49759 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: VMCI: Use threaded irqs instead of tasklets The vmci_dispatch_dgs() tasklet function calls vmci_read_data() which uses wait_event…
CVE-2022-50341 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: cifs: fix oops during encryption When running xfstests against Azure the following oops occurred on an arm64 system Unable to …
CVE-2022-4285 medium 5.5 3y ago RHSA-2023:6236: binutils security update (Moderate)
CVE-2022-31130 medium 5.5 3y ago Moderate: grafana security and enhancement update
CVE-2022-40433 medium 5.5 3y ago RHSA-2023:5731: java-1.8.0-openjdk security update (Moderate)
CVE-2022-46663 medium 5.5 3y ago Moderate: less security update
CVE-2022-48281 medium 5.5 3y ago RHSA-2023:3827: libtiff security update (Moderate)
CVE-2022-50493 medium 5.5 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix crash when I/O abort times out While performing CPU hotplug, a crash with the following stack was seen: Call …
CVE-2022-4515 medium 5.5 3y ago RHSA-2023:2863: ctags security update (Moderate)
CVE-2022-27239 medium 5.5 3y ago RHBA-2023:3052: cifs-utils bug fix and enhancement update (Moderate)
CVE-2022-49058 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: cifs: potential buffer overflow in handling symlinks Smatch printed a warning: arch/x86/crypto/poly1305_glue.c:198 poly1305_upda…
CVE-2022-41973 medium 5.5 3y ago RHSA-2023:2948: device-mapper-multipath security and bug fix update (Moderate)
CVE-2022-39320 medium 5.5 3y ago RHSA-2023:2851: freerdp security update (Moderate)
CVE-2022-48337 medium 5.5 3y ago RHSA-2023:7083: emacs security update (Moderate)
CVE-2022-3736 medium 5.5 3y ago RHSA-2023:2792: bind9.16 security and bug fix update (Moderate)
CVE-2022-3094 medium 5.5 3y ago RHSA-2023:7177: bind security update (Moderate)
CVE-2022-49541 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential double free during failed mount RHBZ: https://bugzilla.redhat.com/show_bug.cgi?id=2088799
CVE-2022-3924 medium 5.5 3y ago RHSA-2023:2792: bind9.16 security and bug fix update (Moderate)
CVE-2022-39316 medium 5.5 3y ago RHSA-2023:2851: freerdp security update (Moderate)
CVE-2022-29187 medium 5.5 3y ago RHSA-2023:2859: git security and bug fix update (Moderate)
CVE-2022-39253 medium 5.5 3y ago RHSA-2023:2859: git security and bug fix update (Moderate)
CVE-2022-50730 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: ext4: silence the warning when evicting inode with dioread_nolock When evicting an inode with default dioread_nolock, it could be…
CVE-2022-50219 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: bpf: Fix KASAN use-after-free Read in compute_effective_progs Syzbot found a Use After Free bug in compute_effective_progs(). The…
CVE-2022-50717 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds check on Transfer Tag ttag is used as an index to get cmd in nvmet_tcp_handle_h2c_data_pdu(), add a bounds …
CVE-2022-41877 medium 5.5 3y ago RHSA-2023:2851: freerdp security update (Moderate)
CVE-2022-50126 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: jbd2: fix assertion 'jh->b_frozen_data == NULL' failure when journal aborted Following process will fail assertion 'jh->b_frozen_…
CVE-2022-50546 medium 5.5 3y ago In the Linux kernel, the following vulnerability has been resolved: ext4: fix uninititialized value in 'ext4_evict_inode' Syzbot found the following issue: =========================================…
CVE-2022-39317 medium 5.5 3y ago RHSA-2023:2851: freerdp security update (Moderate)