CVE-2014-125010
Last Modified: 15 Apr 2025A vulnerability was found in FFmpeg 2.0. It has been rated as critical. Affected by this issue is the function decode_slice_header of the file libavcodec/h64.c. The manipulation leads to memory corruption. The attack may be launched remotely. It is recommended to apply a patch to fix this issue.
CVE-2014-125009
Last Modified: 15 Apr 2025A vulnerability classified as problematic has been found in FFmpeg 2.0. This affects the function add_yblock of the file libavcodec/snow.h. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. It is recommended to apply a patch to fix this issue.
CVE-2014-125008
Last Modified: 15 Apr 2025A vulnerability classified as problematic has been found in FFmpeg 2.0. Affected is the function vorbis_header of the file libavformat/oggparsevorbis.c. The manipulation leads to memory corruption. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue.
CVE-2014-125007
Last Modified: 15 Apr 2025A vulnerability classified as problematic was found in FFmpeg 2.0. Affected by this vulnerability is the function intra_pred of the file libavcodec/hevcpred_template.c. The manipulation leads to memory corruption. The attack can be launched remotely. It is recommended to apply a patch to fix this issue.
CVE-2014-125006
Last Modified: 15 Apr 2025A vulnerability, which was classified as problematic, has been found in FFmpeg 2.0. Affected by this issue is the function output_frame of the file libavcodec/h264.c. The manipulation leads to memory corruption. The attack may be launched remotely. It is recommended to apply a patch to fix this issue.
CVE-2014-125005
Last Modified: 15 Apr 2025A vulnerability, which was classified as problematic, was found in FFmpeg 2.0. This affects the function decode_vol_header of the file libavcodec/mpeg4videodec.c. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. It is recommended to apply a patch to fix this issue.
CVE-2014-125004
Last Modified: 15 Apr 2025A vulnerability has been found in FFmpeg 2.0 and classified as problematic. This vulnerability affects the function decode_hextile of the file libavcodec/vmnc.c. The manipulation leads to memory corruption. The attack can be initiated remotely. It is recommended to apply a patch to fix this issue.
CVE-2014-125003
Last Modified: 15 Apr 2025A vulnerability was found in FFmpeg 2.0 and classified as problematic. This issue affects the function get_siz of the file libavcodec/jpeg2000dec.c. The manipulation leads to memory corruption. The attack may be initiated remotely. It is recommended to apply a patch to fix this issue.
CVE-2014-125002
Last Modified: 15 Apr 2025A vulnerability was found in FFmpeg 2.0. It has been classified as problematic. Affected is the function dnxhd_init_rc of the file libavcodec/dnxhdenc.c. The manipulation leads to memory corruption. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue.
CVE-2022-30537
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-47010
Last Modified: 21 Nov 2024An issue was discovered function pr_function_type in prdbg.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
CVE-2022-33981
Last Modified: 5 May 2025drivers/block/floppy.c in the Linux kernel before 5.17.6 is vulnerable to a denial of service, because of a concurrency use-after-free flaw after deallocating raw_cmd in the raw_cmd_ioctl function.
CVE-2022-33987
Last Modified: 21 Nov 2024The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.
CVE-2022-47011
Last Modified: 21 Nov 2024An issue was discovered function parse_stab_struct_fields in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
CVE-2022-32762
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-29924
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-33141
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-29921
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-32233
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-26084
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-21503
Last Modified: 21 Nov 2024Vulnerability in the Oracle Cloud Infrastructure product of Oracle Cloud Services. Easily exploitable vulnerability allows high privileged attacker with network access to compromise Oracle Cloud Infrastructure. Successful attacks of this vulnerability can result in unauthorized access to Oracle Cloud Infrastructure accessible data. All affected customers were notified of CVE-2022-21503 by Oracle. CVSS 3.1 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
CVE-2022-25871
Last Modified: 21 Nov 2024All versions of package querymen are vulnerable to Prototype Pollution if the parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. Note: This vulnerability derives from an incomplete fix of [CVE-2020-7600](https://security.snyk.io/vuln/SNYK-JS-QUERYMEN-559867).
CVE-2022-25852
Last Modified: 21 Nov 2024All versions of package pg-native; all versions of package libpq are vulnerable to Denial of Service (DoS) when the addons attempt to cast the second argument to an array and fail. This happens for every non-array argument passed. **Note:** pg-native is a mere binding to npm's libpq library, which in turn has the addons and bindings to the actual C libpq library. This means that problems found in pg-native may transitively impact npm's libpq.
CVE-2022-25872
Last Modified: 21 Nov 2024All versions of package fast-string-search are vulnerable to Out-of-bounds Read due to incorrect memory freeing and length calculation for any non-string input as the source. This allows the attacker to read previously allocated memory.
CVE-2022-22138
Last Modified: 21 Nov 2024All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault due to the violation.
CVE-2022-21213
Last Modified: 21 Nov 2024This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn mixes objects into the target object, recursively mixing existing child objects as well. In both cases, the key used to access the target object recursively is not checked, leading to exploiting this vulnerability. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7792](https://security.snyk.io/vuln/SNYK-JS-MOUT-1014544).
CVE-2022-25345
Last Modified: 21 Nov 2024All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash.
CVE-2022-25856
Last Modified: 21 Nov 2024The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read() API in git.go. This could allow arbitrary file reads if the GitArtifactReader is provided a pathname containing a symbolic link or an implicit directory name such as ...
CVE-2022-31874
Last Modified: 21 Nov 2024ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface.
CVE-2022-31873
Last Modified: 21 Nov 2024Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an XSS vulnerability via the prefix parameter in /admin/general.cgi.
CVE-2022-31875
Last Modified: 21 Nov 2024Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an xss vulnerability via the proname parameter in /admin/scheprofile.cgi
CVE-2022-31876
Last Modified: 21 Nov 2024netgear wnap320 router WNAP320_V2.0.3_firmware is vulnerable to Incorrect Access Control via /recreate.php, which can leak all users cookies.
CVE-2022-31941
Last Modified: 21 Nov 2024Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via \rdms\admin?page=user\manage_user&id=.
CVE-2022-31083
Last Modified: 23 Apr 2025Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 4.10.11 and 5.2.2, the certificate in the Parse Server Apple Game Center auth adapter not validated. As a result, authentication could potentially be bypassed by making a fake certificate accessible via certain Apple domains and providing the URL to that certificate in an authData object. Versions 4.0.11 and 5.2.2 prevent this by introducing a new `rootCertificateUrl` property to the Parse Server Apple Game Center auth adapter which takes the URL to the root certificate of Apple's Game Center authentication certificate. If no value is set, the `rootCertificateUrl` property defaults to the URL of the current root certificate as of May 27, 2022. Keep in mind that the root certificate can change at any time and that it is the developer's responsibility to keep the root certificate URL up-to-date when using the Parse Server Apple Game Center auth adapter. There are no known workarounds for this issue.
CVE-2022-32584
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-33895
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-32580
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-33899
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-30606
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-32571
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-33188
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-32288
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-33200
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-33143
Last Modified: 28 May 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-29496
Last Modified: 15 Apr 2025A stack-based buffer overflow vulnerability exists in the BlynkConsole.h runCommand functionality of Blynk -Library v1.0.1. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.
CVE-2022-21806
Last Modified: 15 Apr 2025A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to remote code execution. The device is exposed to attacks from the network.
CVE-2022-21184
Last Modified: 15 Apr 2025An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise 3.5.4, 3.6 and 3.7. A plaintext HTTP request can lead to a disclosure of login credentials. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.
CVE-2022-30422
Last Modified: 21 Nov 2024Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is vulnerable to Remote code execution via the Viewstate parameter.
CVE-2022-32442
Last Modified: 21 Nov 2024u5cms version 8.3.5 is vulnerable to Cross Site Scripting (XSS). When a user accesses the default home page if the parameter passed in is http://127.0.0.1/? "Onmouseover=%27tzgl (96502)%27bad=", it can cause html injection.
CVE-2022-30607
Last Modified: 21 Nov 2024IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow a user to obtain sensitive information due to information properly masked in the control center UI. IBM X-Force ID: 227294.
