CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2022-26762

    Last Modified: 6 May 2025

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. A malicious application may be able to execute arbitrary code with system privileges.

    Published: 1 Nov 2022
    9.8
    Critical

    CVE-2022-27585

    Last Modified: 2 May 2025

    Password recovery vulnerability in SICK SIM1000 FX Partnumber 1097816 and 1097817 with firmware version <1.6.0 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on the system and thereby affecting the confidentiality integrity and availability of the system. An attacker can expect repeatable success by exploiting the vulnerability. The recommended solution is to update the firmware to a version >= 1.6.0 as soon as possible (available in SICK Support Portal).

    Published: 1 Nov 2022
    6.5
    Medium

    CVE-2022-42317

    Last Modified: 5 May 2025

    Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large memory allocations in xenstored: - - by issuing new requests to xenstored without reading the responses, causing the responses to be buffered in memory - - by causing large number of watch events to be generated via setting up multiple xenstore watches and then e.g. deleting many xenstore nodes below the watched path - - by creating as many nodes as allowed with the maximum allowed size and path length in as many transactions as possible - - by accessing many nodes inside a transaction

    Published: 1 Nov 2022
    7.8
    High

    CVE-2022-42827

    Last Modified: 23 Oct 2025

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

    Published: 1 Nov 2022
    5.5
    Medium

    CVE-2022-32827

    Last Modified: 6 May 2025

    A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to cause a denial-of-service.

    Published: 1 Nov 2022
    3.3
    Low

    CVE-2022-32835

    Last Modified: 6 May 2025

    This issue was addressed with improved entitlements. This issue is fixed in iOS 16, watchOS 9. An app may be able to read a persistent device identifier.

    Published: 1 Nov 2022
    5.5
    Medium

    CVE-2022-32858

    Last Modified: 6 May 2025

    The issue was addressed with improved memory handling. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. An app may be able to leak sensitive kernel state.

    Published: 1 Nov 2022
    2.4
    Low

    CVE-2022-32867

    Last Modified: 6 May 2025

    This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. A user with physical access to an iOS device may be able to read past diagnostic logs.

    Published: 1 Nov 2022
    2.4
    Low

    CVE-2022-32870

    Last Modified: 6 May 2025

    A logic issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user with physical access to a device may be able to use Siri to obtain some call history information.

    Published: 1 Nov 2022
    7.8
    High

    CVE-2022-32887

    Last Modified: 6 May 2025

    The issue was addressed with improved memory handling. This issue is fixed in iOS 16. An app may be able to execute arbitrary code with kernel privileges.

    Published: 1 Nov 2022
    7.8
    High

    CVE-2022-32889

    Last Modified: 5 May 2025

    The issue was addressed with improved memory handling. This issue is fixed in iOS 16, watchOS 9. An app may be able to execute arbitrary code with kernel privileges.

    Published: 1 Nov 2022
    8.6
    High

    CVE-2022-32892

    Last Modified: 6 May 2025

    An access issue was addressed with improvements to the sandbox. This issue is fixed in Safari 16, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Ventura 13. A sandboxed process may be able to circumvent sandbox restrictions.

    Published: 1 Nov 2022
    7.8
    High

    CVE-2022-32905

    Last Modified: 6 May 2025

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13. Processing a maliciously crafted DMG file may lead to arbitrary code execution with system privileges.

    Published: 1 Nov 2022
    5.5
    Medium

    CVE-2022-32909

    Last Modified: 6 May 2025

    The issue was addressed with improved handling of caches. This issue is fixed in iOS 16. An app may be able to access user-sensitive data.

    Published: 1 Nov 2022
    7.5
    High

    CVE-2022-32910

    Last Modified: 6 May 2025

    A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS Monterey 12.5, Security Update 2022-005 Catalina. An archive may be able to bypass Gatekeeper.

    Published: 1 Nov 2022
    7.8
    High

    CVE-2022-32915

    Last Modified: 6 May 2025

    A type confusion issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to execute arbitrary code with kernel privileges.

    Published: 1 Nov 2022
    5.5
    Medium

    CVE-2022-32918

    Last Modified: 6 May 2025

    This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to bypass Privacy preferences.

    Published: 1 Nov 2022
    8.8
    High

    CVE-2022-32922

    Last Modified: 6 May 2025

    A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.1, iOS 16.1 and iPadOS 16, macOS Ventura 13. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 1 Nov 2022
    7.8
    High

    CVE-2022-32924

    Last Modified: 6 May 2025

    The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Big Sur 11.7, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6. An app may be able to execute arbitrary code with kernel privileges.

    Published: 1 Nov 2022
    7.1
    High

    CVE-2022-32925

    Last Modified: 6 May 2025

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to cause unexpected system termination or write kernel memory.

    Published: 1 Nov 2022
    7.5
    High

    CVE-2022-32927

    Last Modified: 6 May 2025

    The issue was addressed with improved memory handling. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. Joining a malicious Wi-Fi network may result in a denial-of-service of the Settings app.

    Published: 1 Nov 2022
    5.3
    Medium

    CVE-2022-32928

    Last Modified: 6 May 2025

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A user in a privileged network position may be able to intercept mail credentials.

    Published: 1 Nov 2022
    5.5
    Medium

    CVE-2022-32929

    Last Modified: 6 May 2025

    A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 15.7 and iPadOS 15.7, iOS 16.1 and iPadOS 16. An app may be able to access iOS backups.

    Published: 1 Nov 2022
    8.8
    High

    CVE-2022-32934

    Last Modified: 6 May 2025

    The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, macOS Monterey 12.6. A remote user may be able to cause kernel code execution.

    Published: 1 Nov 2022
    4.6
    Medium

    CVE-2022-32935

    Last Modified: 6 May 2025

    A lock screen issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16, macOS Ventura 13. A user may be able to view restricted content from the lock screen.

    Published: 1 Nov 2022
    5.5
    Medium

    CVE-2022-32936

    Last Modified: 6 May 2025

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13. An app may be able to disclose kernel memory.

    Published: 1 Nov 2022
    5.3
    Medium

    CVE-2022-32938

    Last Modified: 6 May 2025

    A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13. A shortcut may be able to check the existence of an arbitrary path on the file system.

    Published: 1 Nov 2022
    7.8
    High

    CVE-2022-32939

    Last Modified: 6 May 2025

    The issue was addressed with improved bounds checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. An app may be able to execute arbitrary code with kernel privileges.

    Published: 1 Nov 2022
    9.8
    Critical

    CVE-2022-32941

    Last Modified: 6 May 2025

    The issue was addressed with improved bounds checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A buffer overflow may result in arbitrary code execution.

    Published: 1 Nov 2022
    7.8
    High

    CVE-2022-32944

    Last Modified: 6 May 2025

    A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. An app may be able to execute arbitrary code with kernel privileges.

    Published: 1 Nov 2022
    7.8
    High

    CVE-2022-32947

    Last Modified: 6 May 2025

    The issue was addressed with improved memory handling. This issue is fixed in iOS 16.1 and iPadOS 16, macOS Ventura 13, watchOS 9.1. An app may be able to execute arbitrary code with kernel privileges.

    Published: 1 Nov 2022
    8.8
    High

    CVE-2022-3304

    Last Modified: 6 May 2025

    Use after free in CSS in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Nov 2022
    8.8
    High

    CVE-2022-3305

    Last Modified: 6 May 2025

    Use after free in survey in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Nov 2022
    8.8
    High

    CVE-2022-3306

    Last Modified: 6 May 2025

    Use after free in survey in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Nov 2022
    8.8
    High

    CVE-2022-3307

    Last Modified: 6 May 2025

    Use after free in media in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Nov 2022
    7.4
    High

    CVE-2022-3308

    Last Modified: 6 May 2025

    Insufficient policy enforcement in developer tools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Nov 2022
    6.5
    Medium

    CVE-2022-3309

    Last Modified: 6 May 2025

    Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: Medium)

    Published: 1 Nov 2022
    6.5
    Medium

    CVE-2022-3310

    Last Modified: 6 May 2025

    Insufficient policy enforcement in custom tabs in Google Chrome on Android prior to 106.0.5249.62 allowed an attacker who convinced the user to install an application to bypass same origin policy via a crafted application. (Chromium security severity: Medium)

    Published: 1 Nov 2022
    6.5
    Medium

    CVE-2022-3311

    Last Modified: 21 Nov 2024

    Use after free in import in Google Chrome prior to 106.0.5249.62 allowed a remote attacker who had compromised a WebUI process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Nov 2022
    6.5
    Medium

    CVE-2022-3313

    Last Modified: 6 May 2025

    Incorrect security UI in full screen in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Nov 2022
    6.5
    Medium

    CVE-2022-3314

    Last Modified: 6 May 2025

    Use after free in logging in Google Chrome prior to 106.0.5249.62 allowed a remote attacker who had compromised a WebUI process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 1 Nov 2022
    8.8
    High

    CVE-2022-3315

    Last Modified: 21 Nov 2024

    Type confusion in Blink in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

    Published: 1 Nov 2022
    4.3
    Medium

    CVE-2022-3316

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass security feature via a crafted HTML page. (Chromium security severity: Low)

    Published: 1 Nov 2022
    4.3
    Medium

    CVE-2022-3317

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 106.0.5249.62 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 1 Nov 2022
    4.3
    Medium

    CVE-2022-3318

    Last Modified: 21 Nov 2024

    Use after free in ChromeOS Notifications in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to reboot Chrome OS to potentially exploit heap corruption via UI interaction. (Chromium security severity: Low)

    Published: 1 Nov 2022
    8.8
    High

    CVE-2022-3370

    Last Modified: 21 Nov 2024

    Use after free in Custom Elements in Google Chrome prior to 106.0.5249.91 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Nov 2022
    8.8
    High

    CVE-2022-3373

    Last Modified: 5 May 2025

    Out of bounds write in V8 in Google Chrome prior to 106.0.5249.91 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Nov 2022
    4.3
    Medium

    CVE-2022-3444

    Last Modified: 21 Nov 2024

    Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass File System restrictions via a crafted HTML page and malicious file. (Chromium security severity: Low)

    Published: 1 Nov 2022
    6.5
    Medium

    CVE-2022-34662

    Last Modified: 6 May 2025

    When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade to version 3.0.0 or higher

    Published: 1 Nov 2022
    8.8
    High

    CVE-2022-3652

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 1 Nov 2022