CVE Feed

    Dashboard / CVE

    4.4
    Medium

    CVE-2022-20107

    Last Modified: 21 Nov 2024

    In subtitle service, there is a possible application crash due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330673; Issue ID: DTV03330673.

    Published: 3 May 2022
    6.7
    Medium

    CVE-2022-20106

    Last Modified: 21 Nov 2024

    In MM service, there is a possible out of bounds write due to a heap-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330460; Issue ID: DTV03330460.

    Published: 3 May 2022
    6.7
    Medium

    CVE-2022-20105

    Last Modified: 21 Nov 2024

    In MM service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330460; Issue ID: DTV03330460.

    Published: 3 May 2022
    5.5
    Medium

    CVE-2022-20104

    Last Modified: 21 Nov 2024

    In aee daemon, there is a possible information disclosure due to improper access control. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419017; Issue ID: ALPS06284104.

    Published: 3 May 2022
    4.4
    Medium

    CVE-2022-20103

    Last Modified: 21 Nov 2024

    In aee daemon, there is a possible information disclosure due to symbolic link following. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06383944; Issue ID: ALPS06282684.

    Published: 3 May 2022
    4.4
    Medium

    CVE-2022-20102

    Last Modified: 21 Nov 2024

    In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06296442; Issue ID: ALPS06296405.

    Published: 3 May 2022
    5.5
    Medium

    CVE-2022-20101

    Last Modified: 21 Nov 2024

    In aee daemon, there is a possible information disclosure due to a path traversal. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419017; Issue ID: ALPS06270870.

    Published: 3 May 2022
    5.4
    Medium

    CVE-2022-27330

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_product of E-Commerce Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Title text field.

    Published: 3 May 2022
    4.4
    Medium

    CVE-2022-20100

    Last Modified: 21 Nov 2024

    In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06383944; Issue ID: ALPS06270804.

    Published: 3 May 2022
    7.8
    High

    CVE-2022-20099

    Last Modified: 21 Nov 2024

    In aee daemon, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06296442; Issue ID: ALPS06296442.

    Published: 3 May 2022
    4.4
    Medium

    CVE-2022-20098

    Last Modified: 21 Nov 2024

    In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419017; Issue ID: ALPS06419017.

    Published: 3 May 2022
    4.7
    Medium

    CVE-2022-20097

    Last Modified: 21 Nov 2024

    In aee daemon, there is a possible information disclosure due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06383944; Issue ID: ALPS06383944.

    Published: 3 May 2022
    4.4
    Medium

    CVE-2022-20096

    Last Modified: 21 Nov 2024

    In camera, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS06419003; Issue ID: ALPS06419003.

    Published: 3 May 2022
    6.7
    Medium

    CVE-2022-20095

    Last Modified: 21 Nov 2024

    In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479763; Issue ID: ALPS06479763.

    Published: 3 May 2022
    6.7
    Medium

    CVE-2022-20094

    Last Modified: 21 Nov 2024

    In imgsensor, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06479763; Issue ID: ALPS06479734.

    Published: 3 May 2022
    7.8
    High

    CVE-2022-20093

    Last Modified: 21 Nov 2024

    In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06498868; Issue ID: ALPS06498868.

    Published: 3 May 2022
    5.5
    Medium

    CVE-2022-20092

    Last Modified: 21 Nov 2024

    In alac decoder, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06366061; Issue ID: ALPS06366061.

    Published: 3 May 2022
    6.4
    Medium

    CVE-2022-20091

    Last Modified: 21 Nov 2024

    In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06209201; Issue ID: ALPS06226345.

    Published: 3 May 2022
    6.4
    Medium

    CVE-2022-20090

    Last Modified: 21 Nov 2024

    In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06209197; Issue ID: ALPS06209197.

    Published: 3 May 2022
    6.7
    Medium

    CVE-2022-20089

    Last Modified: 21 Nov 2024

    In aee driver, there is a possible memory corruption due to active debug code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06240397; Issue ID: ALPS06240397.

    Published: 3 May 2022
    7.8
    High

    CVE-2022-20088

    Last Modified: 21 Nov 2024

    In aee driver, there is a possible reference count mistake due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06209201; Issue ID: ALPS06209201.

    Published: 3 May 2022
    6.7
    Medium

    CVE-2022-20087

    Last Modified: 21 Nov 2024

    In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06477970; Issue ID: ALPS06477970.

    Published: 3 May 2022
    7.5
    High

    CVE-2022-27313

    Last Modified: 21 Nov 2024

    An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleting the configuration file.

    Published: 3 May 2022
    6.7
    Medium

    CVE-2022-20085

    Last Modified: 21 Nov 2024

    In netdiag, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06308877; Issue ID: ALPS06308877.

    Published: 3 May 2022
    7
    High

    CVE-2022-20110

    Last Modified: 21 Nov 2024

    In ion, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06399915; Issue ID: ALPS06399901.

    Published: 3 May 2022
    7.8
    High

    CVE-2022-20109

    Last Modified: 21 Nov 2024

    In ion, there is a possible use after free due to improper update of reference count. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06399915; Issue ID: ALPS06399915.

    Published: 3 May 2022
    7.8
    High

    CVE-2022-20084

    Last Modified: 21 Nov 2024

    In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06498874; Issue ID: ALPS06498874.

    Published: 3 May 2022
    4.4
    Medium

    CVE-2022-28793

    Last Modified: 21 Nov 2024

    Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent change of Android ROT after first initialization at boot time.

    Published: 3 May 2022
    6.2
    Medium

    CVE-2022-28792

    Last Modified: 21 Nov 2024

    DLL hijacking vulnerability in Gear IconX PC Manager prior to version 2.1.220405.51 allows attacker to execute arbitrary code. The patch adds proper absolute path to prevent dll hijacking.

    Published: 3 May 2022
    6.2
    Medium

    CVE-2022-28791

    Last Modified: 21 Nov 2024

    Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a specific path. The patch adds proper protection to prevent overwrite to existing files.

    Published: 3 May 2022
    4
    Medium

    CVE-2022-28790

    Last Modified: 21 Nov 2024

    Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper caller signature check logic.

    Published: 3 May 2022
    6.2
    Medium

    CVE-2022-28789

    Last Modified: 21 Nov 2024

    Unprotected activities in Voice Note prior to version 21.3.51.11 allows attackers to record voice without user interaction. The patch adds proper permission for vulnerable activities.

    Published: 3 May 2022
    4
    Medium

    CVE-2022-28788

    Last Modified: 21 Nov 2024

    Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

    Published: 3 May 2022
    4
    Medium

    CVE-2022-28787

    Last Modified: 21 Nov 2024

    Improper buffer size check logic in wmfextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

    Published: 3 May 2022
    4
    Medium

    CVE-2022-28786

    Last Modified: 21 Nov 2024

    Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

    Published: 3 May 2022
    4
    Medium

    CVE-2022-28785

    Last Modified: 21 Nov 2024

    Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

    Published: 3 May 2022
    4
    Medium

    CVE-2022-28784

    Last Modified: 21 Nov 2024

    Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arbitrary directory as system user. The patch addresses incorrect implementation of file path validation check logic.

    Published: 3 May 2022
    6.2
    Medium

    CVE-2022-28783

    Last Modified: 21 Nov 2024

    Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages without permission. The patch adds proper validation logic for removing package name.

    Published: 3 May 2022
    4.6
    Medium

    CVE-2022-28782

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Contents To Window prior to SMR May-2022 Release 1 allows physical attacker to install package before completion of Setup wizard. The patch blocks entry point of the vulnerability.

    Published: 3 May 2022
    7.7
    High

    CVE-2022-28781

    Last Modified: 21 Nov 2024

    Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with system privilege. The patch adds proper validation logic to check the caller.

    Published: 3 May 2022
    5
    Medium

    CVE-2022-28780

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in Weather without permission. The patch adds proper protection to prevent access to location information.

    Published: 3 May 2022
    5.5
    Medium

    CVE-2022-1331

    Last Modified: 16 Apr 2025

    In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entities while processing specific project files, which may allow unauthorized information disclosure.

    Published: 3 May 2022
    7.5
    High

    CVE-2022-22368

    Last Modified: 21 Nov 2024

    IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 221012.

    Published: 3 May 2022
    7.2
    High

    CVE-2021-29854

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 205680.

    Published: 3 May 2022
    5.4
    Medium

    CVE-2022-28599

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 that allows an authenticated user to upload a malicious .pdf file which acts as a stored XSS payload. If this stored XSS payload is triggered by an administrator it will trigger a XSS attack.

    Published: 3 May 2022
    7.2
    High

    CVE-2022-29001

    Last Modified: 21 Nov 2024

    In SpringBootMovie <=1.2, the uploaded file suffix parameter is not filtered, resulting in arbitrary file upload vulnerability

    Published: 3 May 2022
    5.4
    Medium

    CVE-2022-28588

    Last Modified: 21 Nov 2024

    In SpringBootMovie <=1.2 when adding movie names, malicious code can be stored because there are no filtering parameters, resulting in stored XSS.

    Published: 3 May 2022
    7.5
    High

    CVE-2021-46440

    Last Modified: 21 Nov 2024

    Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to access a victim's HTTP request, get the victim's cookie, perform a base64 decode on the victim's cookie, and obtain a cleartext password, leading to getting API documentation for further API attacks.

    Published: 3 May 2022
    9.8
    Critical

    CVE-2022-28585

    Last Modified: 21 Nov 2024

    EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php

    Published: 3 May 2022
    9.8
    Critical

    CVE-2022-27962

    Last Modified: 21 Nov 2024

    Bluecms 1.6 has a SQL injection vulnerability at cooike.

    Published: 3 May 2022