Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2022-39125
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
Android
No fix yet
MEDIUM 5.5
CVE-2022-39126
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
Android
Mitigation only
MEDIUM 5.5
CVE-2022-39127
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.
Android
Mitigation only
MEDIUM 5.5
CVE-2022-38679
In music service, there is a missing permission check. This could lead to local denial of service in music service with no additional execution privi…
Android
Mitigation only
MEDIUM 5.5
CVE-2022-38687
In messaging service, there is a missing permission check. This could lead to local denial of service in messaging service with no additional executi…
Android
No fix yet
MEDIUM 5.5
CVE-2022-38677
In cell service, there is a missing permission check. This could lead to local denial of service in cell service with no additional execution privile…
Android
No fix yet
HIGH 7.5
CVE-2022-39278
Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry collection. Prior to versions …
Istio
1.13.9 / 1.14.5+
HIGH 7.5
CVE-2022-41404
An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a Denial of Service (DoS) via …
Debian Linux
0.5.4+
MEDIUM 5.5
CVE-2022-20425
In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent degradation of performance due to resource exhaustion. This could lead to…
Android
Patch available
HIGH 7.5
CVE-2022-39271
Traefik (pronounced traffic) is a modern HTTP reverse proxy and load balancer that assists in deploying microservices. There is a potential vulnerabi…
Traefik
2.8.8+
HIGH 7.5
CVE-2022-38371
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BAC…
Nucleus Net
after 2.3
HIGH 7.5
CVE-2022-39280
dparse is a parser for Python dependency files. dparse in versions before 0.5.2 contain a regular expression that is vulnerable to a Regular Expressi…
Dependency Parser
0.5.1+
HIGH 7.5
CVE-2022-2529
sflow decode package does not employ sufficient packet sanitisation which can lead to a denial of service attack. Attackers can craft malformed packe…
Goflow
3.4.4+
HIGH 7.5
CVE-2022-34326
In ambiot amb1_sdk (aka SDK for Ameba1) before 2022-06-20 on Realtek RTL8195AM devices before 284241d70308ff2519e40afd7b284ba892c730a3, the timer tas…
Rtl8195am Firmware
2022-06-20+
HIGH 7.5
CVE-2022-3204
A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegatio…
Fedora
after 1.16.2
HIGH 7.5
CVE-2022-32790
This issue was addressed with improved checks. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, macOS Bi…
Ipados
8.6 / 10.15.7+
MEDIUM 6.5
CVE-2022-3257
Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which a…
Mattermost Server
7.2.0+
MEDIUM 5.5
CVE-2022-23951
In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.
Keylime
6.3.0+
HIGH 8.8
CVE-2022-28639
A remote potential adjacent denial of service (DoS) and potential adjacent arbitrary code execution vulnerability that could potentially lead to a lo…
Integrated Lights Out 5 Firmware
2.72+
HIGH 7.5
CVE-2022-37884
A vulnerability exists in the ClearPass Policy Manager Guest User Interface that can allow an unauthenticated attacker to send specific operations wh…
Clearpass Policy Manager
6.9.12 / 6.10.7+
HIGH 7.5
CVE-2022-28204
A denial-of-service issue was discovered in MediaWiki 1.37.x before 1.37.2. Rendering of w/index.php?title=Special%3AWhatLinksHere&target=Property%3A…
Mediawiki
1.37.2+
HIGH 7.5
CVE-2022-40150
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user suppl…
Debian Linux
after 1.4.0
MEDIUM 6.5
CVE-2022-39209
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time…
Cmark Gfm
0.29.0.gfm.6+
MEDIUM 6.5
CVE-2022-36114
Cargo is a package manager for the rust programming language. It was discovered that Cargo did not limit the amount of data extracted from compressed…
Cargo
0.65.0+
HIGH 7.8
CVE-2022-2962
A DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descriptor or copies the rx/tx frame,…
Qemu
after 7.1.0
HIGH 7.5
CVE-2022-38013
.NET Core and Visual Studio Denial of Service Vulnerability
Fedora
Patch available
HIGH 7.5
CVE-2022-38100
The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with network access can remotely issu…
Cms8000 Firmware
Mitigation only
MEDIUM 5.3
CVE-2022-39158
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCO…
Ruggedcom Ros
5.6.0+
HIGH 7.5
CVE-2022-31006
indy-node is the server portion of Hyperledger Indy, a distributed ledger purpose-built for decentralized identity. In vulnerable versions of indy-no…
Indy Node
after 1.12.6
MEDIUM 6.5
CVE-2022-3147
Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated…
Mattermost Server
7.1.0+