CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2022-42011

    Last Modified: 9 Jun 2025

    An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.

    Published: 5 Oct 2022
    6.5
    Medium

    CVE-2022-42012

    Last Modified: 9 Jun 2025

    An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.

    Published: 5 Oct 2022
    6.5
    Medium

    CVE-2022-42010

    Last Modified: 9 Jun 2025

    An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.

    Published: 5 Oct 2022
    6.5
    Medium

    CVE-2022-2928

    Last Modified: 21 Nov 2024

    In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function option_code_hash_lookup() is called from add_option(), it increases the option's refcount field. However, there is not a corresponding call to option_dereference() to decrement the refcount field. The function add_option() is only used in server responses to lease query packets. Each lease query response calls this function for several options, so eventually, the reference counters could overflow and cause the server to abort.

    Published: 5 Oct 2022
    6.5
    Medium

    CVE-2022-2929

    Last Modified: 21 Nov 2024

    In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run out of memory.

    Published: 5 Oct 2022
    5.5
    Medium

    CVE-2022-31008

    Last Modified: 23 Apr 2025

    RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. This issue has been addressed and Patched versions: `3.10.2`, `3.9.18`, `3.8.32` are available. Users unable to upgrade should disable the Shovel and Federation plugins.

    Published: 5 Oct 2022
    5.5
    Medium

    CVE-2022-3644

    Last Modified: 7 May 2025

    The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.

    Published: 4 Oct 2022
    7.5
    High

    CVE-2022-41323

    Last Modified: 14 May 2025

    In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.

    Published: 4 Oct 2022
    8.4
    High

    CVE-2022-3276

    Last Modified: 21 Nov 2024

    Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsanitized input to the module. This condition is rare in most deployments of Puppet and Puppet Enterprise.

    Published: 4 Oct 2022
    7.5
    High

    CVE-2022-2879

    Last Modified: 13 Feb 2025

    Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB.

    Published: 4 Oct 2022
    7.5
    High

    CVE-2022-2880

    Last Modified: 13 Feb 2025

    Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request's Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged.

    Published: 4 Oct 2022
    5.5
    Medium

    CVE-2022-3564

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211087.

    Published: 4 Oct 2022
    7.5
    High

    CVE-2022-41715

    Last Modified: 13 Feb 2025

    Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively small regexps consume much larger amounts of memory. After fix, each regexp being parsed is limited to a 256 MB memory footprint. Regular expressions whose representation would use more space than that are rejected. Normal use of regular expressions is unaffected.

    Published: 4 Oct 2022
    —
    Unknown

    CVE-2022-42337

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 3 Oct 2022
    —
    Unknown

    CVE-2022-42338

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 3 Oct 2022
    6.1
    Medium

    CVE-2022-42247

    Last Modified: 21 Nov 2024

    pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a file name.

    Published: 3 Oct 2022
    9.8
    Critical

    CVE-2022-41443

    Last Modified: 21 Nov 2024

    phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.

    Published: 3 Oct 2022
    —
    Unknown

    CVE-2022-3404

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 3 Oct 2022
    —
    Unknown

    CVE-2022-3403

    Last Modified: 7 Nov 2023

    Duplicate, please use CVE-2023-28931 instead.

    Published: 3 Oct 2022
    9.8
    Critical

    CVE-2022-33882

    Last Modified: 21 Nov 2024

    Under certain conditions, an attacker could create an unintended sphere of control through a vulnerability present in file delete operation in Autodesk desktop app (ADA). An attacker could leverage this vulnerability to escalate privileges and execute arbitrary code.

    Published: 3 Oct 2022
    9.8
    Critical

    CVE-2022-40721

    Last Modified: 21 Nov 2024

    Arbitrary file upload vulnerability in php uploader

    Published: 3 Oct 2022
    5.3
    Medium

    CVE-2022-42299

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to a denial of service attack through the DiscoveryService service.

    Published: 3 Oct 2022
    4.3
    Medium

    CVE-2022-42300

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server nbars process can be crashed resulting in a denial of service. (Note: the watchdog service will automatically restart the process.)

    Published: 3 Oct 2022
    5.4
    Medium

    CVE-2022-42301

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) injection attack through the nbars process.

    Published: 3 Oct 2022
    9
    Critical

    CVE-2022-42302

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a SQL Injection attack affecting the NBFSMCLIENT service.

    Published: 3 Oct 2022
    8
    High

    CVE-2022-42303

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a second-order SQL Injection attack affecting the NBFSMCLIENT service by leveraging CVE-2022-42302.

    Published: 3 Oct 2022
    8
    High

    CVE-2022-42304

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a SQL Injection attack affecting idm, nbars, and SLP manager code.

    Published: 3 Oct 2022
    5.3
    Medium

    CVE-2022-42305

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to a Path traversal attack through the DiscoveryService service.

    Published: 3 Oct 2022
    6.5
    Medium

    CVE-2022-42306

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can send a crafted packet to pbx_exchange during registration and cause a NULL pointer exception, effectively crashing the pbx_exchange process.

    Published: 3 Oct 2022
    5.3
    Medium

    CVE-2022-42307

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML External Entity (XXE) Injection attack through the DiscoveryService service.

    Published: 3 Oct 2022
    9
    Critical

    CVE-2022-42308

    Last Modified: 21 Nov 2024

    An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can delete arbitrary files by leveraging a path traversal in the pbx_exchange registration code.

    Published: 3 Oct 2022
    7.8
    High

    CVE-2022-33883

    Last Modified: 21 Nov 2024

    A malicious crafted file consumed through Moldflow Synergy, Moldflow Adviser, Moldflow Communicator, and Advanced Material Exchange applications could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 3 Oct 2022
    7.8
    High

    CVE-2022-33888

    Last Modified: 20 May 2025

    A malicious crafted Dwg2Spd file when processed through Autodesk DWG application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 3 Oct 2022
    7.8
    High

    CVE-2022-33887

    Last Modified: 21 Nov 2024

    A maliciously crafted PDF file when parsed through Autodesk AutoCAD 2023 causes an unhandled exception. An attacker can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code in the context of the current process.

    Published: 3 Oct 2022
    7.8
    High

    CVE-2022-33885

    Last Modified: 21 Nov 2024

    A maliciously crafted X_B, CATIA, and PDF file when parsed through Autodesk AutoCAD 2023 and 2022 can be used to write beyond the allocated buffer. This vulnerability can lead to arbitrary code execution.

    Published: 3 Oct 2022
    7.5
    High

    CVE-2022-33884

    Last Modified: 21 Nov 2024

    Parsing a maliciously crafted X_B file can force Autodesk AutoCAD 2023 and 2022 to read beyond allocated boundaries. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

    Published: 3 Oct 2022
    7.8
    High

    CVE-2022-33889

    Last Modified: 21 Nov 2024

    A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD 2023 and 2022 could be used to write beyond the allocated heap buffer. This vulnerability could lead to arbitrary code execution.

    Published: 3 Oct 2022
    8.8
    High

    CVE-2022-41430

    Last Modified: 21 Nov 2024

    Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux.

    Published: 3 Oct 2022
    8.8
    High

    CVE-2022-41429

    Last Modified: 21 Nov 2024

    Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_Atom::TypeFromString function in mp4tag.

    Published: 3 Oct 2022
    8.8
    High

    CVE-2022-41428

    Last Modified: 21 Nov 2024

    Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBits function in mp4mux.

    Published: 3 Oct 2022
    6.5
    Medium

    CVE-2022-41427

    Last Modified: 21 Nov 2024

    Bento4 v1.6.0-639 was discovered to contain a memory leak in the AP4_AvcFrameParser::Feed function in mp4mux.

    Published: 3 Oct 2022
    6.5
    Medium

    CVE-2022-41426

    Last Modified: 21 Nov 2024

    Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_AtomFactory::CreateAtomFromStream function in mp4split.

    Published: 3 Oct 2022
    6.5
    Medium

    CVE-2022-41425

    Last Modified: 21 Nov 2024

    Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4decrypt.

    Published: 3 Oct 2022
    6.5
    Medium

    CVE-2022-41423

    Last Modified: 21 Nov 2024

    Bento4 v1.6.0-639 was discovered to contain a segmentation violation in the mp4fragment component.

    Published: 3 Oct 2022
    6.5
    Medium

    CVE-2022-41424

    Last Modified: 21 Nov 2024

    Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_SttsAtom::Create function in mp42hls.

    Published: 3 Oct 2022
    6.5
    Medium

    CVE-2022-41419

    Last Modified: 21 Nov 2024

    Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_Processor::Process function in the mp4encrypt binary.

    Published: 3 Oct 2022
    —
    Unknown

    CVE-2022-1480

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 3 Oct 2022
    4.8
    Medium

    CVE-2022-3132

    Last Modified: 21 Nov 2024

    The Goolytics WordPress plugin before 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 3 Oct 2022
    4.8
    Medium

    CVE-2022-3128

    Last Modified: 21 Nov 2024

    The Donation Thermometer WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 3 Oct 2022
    8.8
    High

    CVE-2022-3125

    Last Modified: 21 Nov 2024

    The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary extension, like PHP, which could allow them to basically be able to upload arbitrary files on the server and achieve RCE

    Published: 3 Oct 2022