CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2022-42790

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, macOS Monterey 12.6. A user may be able to view restricted content from the lock screen.

    Published: 1 Nov 2022
    7
    High

    CVE-2022-42791

    Last Modified: 5 May 2025

    A race condition was addressed with improved state handling. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code with kernel privileges.

    Published: 1 Nov 2022
    5.5
    Medium

    CVE-2022-42793

    Last Modified: 22 Apr 2025

    An issue in code signature validation was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, macOS Monterey 12.6. An app may be able to bypass code signing checks.

    Published: 1 Nov 2022
    7.8
    High

    CVE-2022-42796

    Last Modified: 22 Apr 2025

    This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.7 and iPadOS 15.7, macOS Ventura 13. An app may be able to gain elevated privileges.

    Published: 1 Nov 2022
    5.5
    Medium

    CVE-2022-42798

    Last Modified: 5 May 2025

    The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. Parsing a maliciously crafted audio file may lead to disclosure of user information.

    Published: 1 Nov 2022
    7.8
    High

    CVE-2022-42800

    Last Modified: 22 Apr 2025

    This issue was addressed with improved checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A user may be able to cause unexpected app termination or arbitrary code execution.

    Published: 1 Nov 2022
    7
    High

    CVE-2022-42803

    Last Modified: 22 Apr 2025

    A race condition was addressed with improved locking. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1. An app may be able to execute arbitrary code with kernel privileges.

    Published: 1 Nov 2022
    9.8
    Critical

    CVE-2022-42808

    Last Modified: 22 Apr 2025

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. A remote user may be able to cause kernel code execution.

    Published: 1 Nov 2022
    7.8
    High

    CVE-2022-42809

    Last Modified: 22 Apr 2025

    The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13. Processing a maliciously crafted gcx file may lead to unexpected app termination or arbitrary code execution.

    Published: 1 Nov 2022
    5.5
    Medium

    CVE-2022-42810

    Last Modified: 22 Apr 2025

    The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13. Processing a maliciously crafted USD file may disclose memory contents.

    Published: 1 Nov 2022
    9.8
    Critical

    CVE-2022-42813

    Last Modified: 22 Apr 2025

    A certificate validation issue existed in the handling of WKWebView. This issue was addressed with improved validation. This issue is fixed in tvOS 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. Processing a maliciously crafted certificate may lead to arbitrary code execution.

    Published: 1 Nov 2022
    5.5
    Medium

    CVE-2022-42814

    Last Modified: 22 Apr 2025

    A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.

    Published: 1 Nov 2022
    5.5
    Medium

    CVE-2022-42815

    Last Modified: 21 Apr 2025

    This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.

    Published: 1 Nov 2022
    6.5
    Medium

    CVE-2022-42817

    Last Modified: 21 Apr 2025

    A logic issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16, watchOS 9.1. Visiting a maliciously crafted website may leak sensitive data.

    Published: 1 Nov 2022
    5.9
    Medium

    CVE-2022-42818

    Last Modified: 21 Apr 2025

    This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. A user in a privileged network position may be able to track user activity.

    Published: 1 Nov 2022
    5.5
    Medium

    CVE-2022-42819

    Last Modified: 21 Apr 2025

    An access issue was addressed with improved access restrictions. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, macOS Monterey 12.6. An app may be able to read sensitive location information.

    Published: 1 Nov 2022
    7.8
    High

    CVE-2022-42820

    Last Modified: 21 Apr 2025

    A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app may cause unexpected app termination or arbitrary code execution.

    Published: 1 Nov 2022
    5.5
    Medium

    CVE-2022-42825

    Last Modified: 21 Apr 2025

    This issue was addressed by removing additional entitlements. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. An app may be able to modify protected parts of the file system.

    Published: 1 Nov 2022
    6.7
    Medium

    CVE-2022-42829

    Last Modified: 21 Apr 2025

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app with root privileges may be able to execute arbitrary code with kernel privileges.

    Published: 1 Nov 2022
    6.7
    Medium

    CVE-2022-42830

    Last Modified: 21 Apr 2025

    The issue was addressed with improved memory handling. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app with root privileges may be able to execute arbitrary code with kernel privileges.

    Published: 1 Nov 2022
    6.4
    Medium

    CVE-2022-42831

    Last Modified: 21 Apr 2025

    A race condition was addressed with improved locking. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app with root privileges may be able to execute arbitrary code with kernel privileges.

    Published: 1 Nov 2022
    6.4
    Medium

    CVE-2022-42832

    Last Modified: 21 Apr 2025

    A race condition was addressed with improved locking. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. An app with root privileges may be able to execute arbitrary code with kernel privileges.

    Published: 1 Nov 2022
    7.2
    High

    CVE-2022-43354

    Last Modified: 2 May 2025

    Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/manage_request.

    Published: 1 Nov 2022
    4.8
    Medium

    CVE-2022-43076

    Last Modified: 5 May 2025

    A cross-site scripting (XSS) vulnerability in /admin/edit-admin.php of Web-Based Student Clearance System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtemail parameter.

    Published: 1 Nov 2022
    7.5
    High

    CVE-2022-43081

    Last Modified: 5 May 2025

    Fast Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /fastfood/purchase.php.

    Published: 1 Nov 2022
    7.2
    High

    CVE-2022-43083

    Last Modified: 5 May 2025

    An arbitrary file upload vulnerability in admin-add-vehicle.php of Vehicle Booking System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

    Published: 1 Nov 2022
    4.8
    Medium

    CVE-2022-43084

    Last Modified: 5 May 2025

    A cross-site scripting (XSS) vulnerability in admin-add-vehicle.php of Vehicle Booking System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the v_name parameter.

    Published: 1 Nov 2022
    7.2
    High

    CVE-2022-43124

    Last Modified: 5 May 2025

    Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user.

    Published: 1 Nov 2022
    7.2
    High

    CVE-2022-43125

    Last Modified: 5 May 2025

    Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/manage_appointment.php.

    Published: 1 Nov 2022
    7.2
    High

    CVE-2022-43127

    Last Modified: 5 May 2025

    Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/update_status.php.

    Published: 1 Nov 2022
    7.5
    High

    CVE-2022-43221

    Last Modified: 2 May 2025

    open5gs v2.4.11 was discovered to contain a memory leak in the component src/upf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.

    Published: 1 Nov 2022
    7.5
    High

    CVE-2022-43223

    Last Modified: 2 May 2025

    open5gs v2.4.11 was discovered to contain a memory leak in the component ngap-handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted UE attachment.

    Published: 1 Nov 2022
    7.2
    High

    CVE-2022-43329

    Last Modified: 2 May 2025

    Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php.

    Published: 1 Nov 2022
    7.2
    High

    CVE-2022-43353

    Last Modified: 2 May 2025

    Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order.

    Published: 1 Nov 2022
    7.2
    High

    CVE-2022-43355

    Last Modified: 2 May 2025

    Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-sms/classes/Master.php?f=delete_service.

    Published: 1 Nov 2022
    4.8
    Medium

    CVE-2022-43361

    Last Modified: 5 May 2025

    Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component pop_chart.php.

    Published: 1 Nov 2022
    7.2
    High

    CVE-2022-43362

    Last Modified: 5 May 2025

    Senayan Library Management System v9.4.2 was discovered to contain a SQL injection vulnerability via the collType parameter at loan_by_class.php.

    Published: 1 Nov 2022
    9.8
    Critical

    CVE-2022-44542

    Last Modified: 5 May 2025

    lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object destructor execution via a key/value pair in a hash.

    Published: 1 Nov 2022
    5.3
    Medium

    CVE-2022-32859

    Last Modified: 6 May 2025

    A logic issue was addressed with improved state management. This issue is fixed in iOS 16. Deleted contacts may still appear in spotlight search results.

    Published: 1 Nov 2022
    5.5
    Medium

    CVE-2022-32862

    Last Modified: 6 May 2025

    This issue was addressed with improved data protection. This issue is fixed in macOS Big Sur 11.7.1, macOS Ventura 13, macOS Monterey 12.6.1. An app with root privileges may be able to access private information.

    Published: 1 Nov 2022
    7.8
    High

    CVE-2022-32866

    Last Modified: 6 May 2025

    The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, watchOS 9, macOS Monterey 12.6, tvOS 16. An app may be able to execute arbitrary code with kernel privileges.

    Published: 1 Nov 2022
    7.8
    High

    CVE-2022-32898

    Last Modified: 5 May 2025

    The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7 and iPadOS 15.7, iOS 16, macOS Ventura 13, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.

    Published: 1 Nov 2022
    6.5
    Medium

    CVE-2022-42318

    Last Modified: 5 May 2025

    Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large memory allocations in xenstored: - - by issuing new requests to xenstored without reading the responses, causing the responses to be buffered in memory - - by causing large number of watch events to be generated via setting up multiple xenstore watches and then e.g. deleting many xenstore nodes below the watched path - - by creating as many nodes as allowed with the maximum allowed size and path length in as many transactions as possible - - by accessing many nodes inside a transaction

    Published: 1 Nov 2022
    6.5
    Medium

    CVE-2022-42319

    Last Modified: 21 Nov 2024

    Xenstore: Guests can cause Xenstore to not free temporary memory When working on a request of a guest, xenstored might need to allocate quite large amounts of memory temporarily. This memory is freed only after the request has been finished completely. A request is regarded to be finished only after the guest has read the response message of the request from the ring page. Thus a guest not reading the response can cause xenstored to not free the temporary memory. This can result in memory shortages causing Denial of Service (DoS) of xenstored.

    Published: 1 Nov 2022
    8.8
    High

    CVE-2022-42309

    Last Modified: 21 Nov 2024

    Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during node creation in an error path, resulting in a crash of xenstored or a memory corruption in xenstored causing further damage. Entering the error path can be controlled by the guest e.g. by exceeding the quota value of maximum nodes per domain.

    Published: 1 Nov 2022
    5.5
    Medium

    CVE-2022-42310

    Last Modified: 21 Nov 2024

    Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes inside a transaction resulting in an error, a malicious guest can create orphaned nodes in the Xenstore data base, as the cleanup after the error will not remove all nodes already created. When the transaction is committed after this situation, nodes without a valid parent can be made permanent in the data base.

    Published: 1 Nov 2022
    6.5
    Medium

    CVE-2022-42311

    Last Modified: 6 May 2025

    Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large memory allocations in xenstored: - - by issuing new requests to xenstored without reading the responses, causing the responses to be buffered in memory - - by causing large number of watch events to be generated via setting up multiple xenstore watches and then e.g. deleting many xenstore nodes below the watched path - - by creating as many nodes as allowed with the maximum allowed size and path length in as many transactions as possible - - by accessing many nodes inside a transaction

    Published: 1 Nov 2022
    6.5
    Medium

    CVE-2022-42313

    Last Modified: 6 May 2025

    Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large memory allocations in xenstored: - - by issuing new requests to xenstored without reading the responses, causing the responses to be buffered in memory - - by causing large number of watch events to be generated via setting up multiple xenstore watches and then e.g. deleting many xenstore nodes below the watched path - - by creating as many nodes as allowed with the maximum allowed size and path length in as many transactions as possible - - by accessing many nodes inside a transaction

    Published: 1 Nov 2022
    6.5
    Medium

    CVE-2022-42316

    Last Modified: 5 May 2025

    Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large memory allocations in xenstored: - - by issuing new requests to xenstored without reading the responses, causing the responses to be buffered in memory - - by causing large number of watch events to be generated via setting up multiple xenstore watches and then e.g. deleting many xenstore nodes below the watched path - - by creating as many nodes as allowed with the maximum allowed size and path length in as many transactions as possible - - by accessing many nodes inside a transaction

    Published: 1 Nov 2022
    7.5
    High

    CVE-2022-25892

    Last Modified: 6 May 2025

    The package muhammara before 2.6.1, from 3.0.0 and before 3.1.1; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed.

    Published: 1 Nov 2022