CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2021-33461

    Last Modified: 21 Nov 2024

    An issue was discovered in yasm version 1.3.0. There is a use-after-free in yasm_intnum_destroy() in libyasm/intnum.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33462

    Last Modified: 21 Nov 2024

    An issue was discovered in yasm version 1.3.0. There is a use-after-free in expr_traverse_nodes_post() in libyasm/expr.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33463

    Last Modified: 21 Nov 2024

    An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in yasm_expr__copy_except() in libyasm/expr.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33464

    Last Modified: 21 Nov 2024

    An issue was discovered in yasm version 1.3.0. There is a heap-buffer-overflow in inc_fopen() in modules/preprocs/nasm/nasm-pp.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33465

    Last Modified: 21 Nov 2024

    An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmacro() in modules/preprocs/nasm/nasm-pp.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33466

    Last Modified: 21 Nov 2024

    An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_smacro() in modules/preprocs/nasm/nasm-pp.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33467

    Last Modified: 21 Nov 2024

    An issue was discovered in yasm version 1.3.0. There is a use-after-free in pp_getline() in modules/preprocs/nasm/nasm-pp.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33468

    Last Modified: 21 Nov 2024

    An issue was discovered in yasm version 1.3.0. There is a use-after-free in error() in modules/preprocs/nasm/nasm-pp.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33460

    Last Modified: 21 Nov 2024

    An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in if_condition() in modules/preprocs/nasm/nasm-pp.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33459

    Last Modified: 21 Nov 2024

    An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in nasm_parser_directive() in modules/parsers/nasm/nasm-parse.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33458

    Last Modified: 21 Nov 2024

    An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in find_cc() in modules/preprocs/nasm/nasm-pp.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33457

    Last Modified: 21 Nov 2024

    An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmac_params() in modules/preprocs/nasm/nasm-pp.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33456

    Last Modified: 21 Nov 2024

    An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in hash() in modules/preprocs/nasm/nasm-pp.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33455

    Last Modified: 21 Nov 2024

    An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in do_directive() in modules/preprocs/nasm/nasm-pp.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33454

    Last Modified: 21 Nov 2024

    An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in yasm_expr_get_intnum() in libyasm/expr.c.

    Published: 26 Jul 2022
    7.8
    High

    CVE-2021-33453

    Last Modified: 21 Nov 2024

    An issue was discovered in lrzip version 0.641. There is a use-after-free in ucompthread() in stream.c:1538.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33451

    Last Modified: 21 Nov 2024

    An issue was discovered in lrzip version 0.641. There are memory leaks in fill_buffer() in stream.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33443

    Last Modified: 21 Nov 2024

    An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow in mjs_execute() in mjs.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33444

    Last Modified: 21 Nov 2024

    An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in getprop_builtin_foreign() in mjs.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33445

    Last Modified: 21 Nov 2024

    An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_string_char_code_at() in mjs.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33446

    Last Modified: 21 Nov 2024

    An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_next() in mjs.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33447

    Last Modified: 21 Nov 2024

    An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_print() in mjs.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33448

    Last Modified: 21 Nov 2024

    An issue was discovered in mjs(mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow at 0x7fffe9049390.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33449

    Last Modified: 21 Nov 2024

    An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_bcode_part_get_by_offset() in mjs.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33442

    Last Modified: 21 Nov 2024

    An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in json_printf() in mjs.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33441

    Last Modified: 21 Nov 2024

    An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in exec_expr() in mjs.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33440

    Last Modified: 21 Nov 2024

    An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_bcode_commit() in mjs.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33439

    Last Modified: 21 Nov 2024

    An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is Integer overflow in gc_compact_strings() in mjs.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33438

    Last Modified: 21 Nov 2024

    An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow in json_parse_array() in mjs.c.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2021-33437

    Last Modified: 21 Nov 2024

    An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There are memory leaks in frozen_cb() in mjs.c.

    Published: 26 Jul 2022
    8.1
    High

    CVE-2022-2225

    Last Modified: 21 Nov 2024

    By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to bypass configured Zero Trust security policies (e.g. Secure Web Gateway policies) and features such as 'Lock WARP switch'.

    Published: 26 Jul 2022
    7.5
    High

    CVE-2022-36946

    Last Modified: 5 May 2025

    nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload attribute, an skb_pull can encounter a negative skb->len.

    Published: 26 Jul 2022
    5.7
    Medium

    CVE-2021-43959

    Last Modified: 21 Nov 2024

    Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability in the CSV importing feature of JSM Insight. When running in an environment like Amazon EC2, this flaw may be used to access to a metadata resource that provides access credentials and other potentially confidential information. The affected versions are before version 4.13.20, from version 4.14.0 before 4.20.8, and from version 4.21.0 before 4.22.2.

    Published: 26 Jul 2022
    7.5
    High

    CVE-2022-33977

    Last Modified: 21 Nov 2024

    untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts recursive entity references in DTDs. By exploiting this vulnerability, a remote unauthenticated attacker may cause a denial-of-service (DoS) condition on the server where the product is running.

    Published: 26 Jul 2022
    7.5
    High

    CVE-2022-31471

    Last Modified: 21 Nov 2024

    untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts XML external entity references. By exploiting this vulnerability, a remote unauthenticated attacker may read the contents of local files.

    Published: 26 Jul 2022
    6.1
    Medium

    CVE-2022-30706

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in Booked versions prior to 3.3 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.

    Published: 26 Jul 2022
    8.2
    High

    CVE-2022-1042

    Last Modified: 21 Nov 2024

    In Zephyr bluetooth mesh core stack, an out-of-bound write vulnerability can be triggered during provisioning.

    Published: 26 Jul 2022
    8.2
    High

    CVE-2022-1041

    Last Modified: 21 Nov 2024

    In Zephyr bluetooth mesh core stack, an out-of-bound write vulnerability can be triggered during provisioning.

    Published: 26 Jul 2022
    5.4
    Medium

    CVE-2020-36290

    Last Modified: 21 Nov 2024

    The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the page excerpt functionality.

    Published: 26 Jul 2022
    6.5
    Medium

    CVE-2022-22686

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote authenticated users to hijack the authentication of administrators via unspecified vectors.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-33745

    Last Modified: 21 Nov 2024

    insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside a function in Xen. This code movement missed a variable changing meaning / value between old and new code positions. The now wrong use of the variable did lead to a wrong TLB flush condition, omitting flushes where such are necessary.

    Published: 26 Jul 2022
    7.5
    High

    CVE-2022-36319

    Last Modified: 15 Apr 2025

    When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.

    Published: 26 Jul 2022
    5.5
    Medium

    CVE-2022-36314

    Last Modified: 15 Apr 2025

    When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.<br>This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1.

    Published: 26 Jul 2022
    5.3
    Medium

    CVE-2022-36318

    Last Modified: 15 Apr 2025

    When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.

    Published: 26 Jul 2022
    8.8
    High

    CVE-2022-2505

    Last Modified: 15 Apr 2025

    Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1.

    Published: 26 Jul 2022
    9.8
    Critical

    CVE-2022-34577

    Last Modified: 21 Nov 2024

    A vulnerability in adm.cgi of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.

    Published: 25 Jul 2022
    7.5
    High

    CVE-2022-34576

    Last Modified: 21 Nov 2024

    A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.

    Published: 25 Jul 2022
    5.7
    Medium

    CVE-2022-34575

    Last Modified: 21 Nov 2024

    An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing fctest.shtml.

    Published: 25 Jul 2022
    5.7
    Medium

    CVE-2022-34574

    Last Modified: 21 Nov 2024

    An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing Tftpd32.ini.

    Published: 25 Jul 2022
    6.3
    Medium

    CVE-2022-34573

    Last Modified: 21 Nov 2024

    An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to arbitrarily configure device settings via accessing the page mb_wifibasic.shtml.

    Published: 25 Jul 2022