CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2022-0326

    Last Modified: 21 Nov 2024

    NULL Pointer Dereference in Homebrew mruby prior to 3.2.

    Published: 21 Jan 2022
    6.5
    Medium

    CVE-2021-46243

    Last Modified: 21 Nov 2024

    An untrusted pointer dereference vulnerability exists in HDF5 v1.13.1-1 via the function H5O__dtype_decode_helper () at hdf5/src/H5Odtype.c. This vulnerability can lead to a Denial of Service (DoS).

    Published: 21 Jan 2022
    6.5
    Medium

    CVE-2021-46244

    Last Modified: 21 Nov 2024

    A Divide By Zero vulnerability exists in HDF5 v1.13.1-1 vis the function H5T__complete_copy () at /hdf5/src/H5T.c. This vulnerability causes an aritmetic exception, leading to a Denial of Service (DoS).

    Published: 21 Jan 2022
    5.5
    Medium

    CVE-2022-0319

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in vim/vim prior to 8.2.

    Published: 21 Jan 2022
    5.6
    Medium

    CVE-2022-23816

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Jan 2022
    —
    Unknown

    CVE-2022-23827

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Jan 2022
    —
    Unknown

    CVE-2022-23832

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Jan 2022
    6.5
    Medium

    CVE-2020-19860

    Last Modified: 21 Nov 2024

    When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zone file payload.

    Published: 21 Jan 2022
    8.8
    High

    CVE-2021-46242

    Last Modified: 21 Nov 2024

    HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.

    Published: 21 Jan 2022
    7.3
    High

    CVE-2021-23518

    Last Modified: 21 Nov 2024

    The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573

    Published: 21 Jan 2022
    6.5
    Medium

    CVE-2022-22594

    Last Modified: 21 Nov 2024

    A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. A website may be able to track sensitive user information.

    Published: 21 Jan 2022
    7.8
    High

    CVE-2022-23220

    Last Modified: 21 Nov 2024

    USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g., allow_any=yes) for pkexec disable the authentication requirement. Code execution can, for example, use the --gtk-module option. This affects Ubuntu, Debian, and Gentoo.

    Published: 21 Jan 2022
    7.5
    High

    CVE-2022-23837

    Last Modified: 21 Nov 2024

    In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.

    Published: 21 Jan 2022
    5.5
    Medium

    CVE-2022-48554

    Last Modified: 21 Nov 2024

    File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project.

    Published: 21 Jan 2022
    9.8
    Critical

    CVE-2022-22930

    Last Modified: 21 Nov 2024

    A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code via a crafted payload.

    Published: 20 Jan 2022
    9.8
    Critical

    CVE-2022-23314

    Last Modified: 21 Nov 2024

    MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.

    Published: 20 Jan 2022
    9.8
    Critical

    CVE-2022-23315

    Last Modified: 21 Nov 2024

    MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.

    Published: 20 Jan 2022
    9.8
    Critical

    CVE-2022-22929

    Last Modified: 21 Nov 2024

    MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file.

    Published: 20 Jan 2022
    9.8
    Critical

    CVE-2022-22928

    Last Modified: 21 Nov 2024

    MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.

    Published: 20 Jan 2022
    7.8
    High

    CVE-2022-22895

    Last Modified: 21 Nov 2024

    Jerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via ecma_utf8_string_to_number_by_radix in /jerry-core/ecma/base/ecma-helpers-conversion.c.

    Published: 20 Jan 2022
    7.8
    High

    CVE-2022-22894

    Last Modified: 21 Nov 2024

    Jerryscript 3.0.0 was discovered to contain a stack overflow via ecma_lcache_lookup in /jerry-core/ecma/base/ecma-lcache.c.

    Published: 20 Jan 2022
    7.8
    High

    CVE-2022-22893

    Last Modified: 21 Nov 2024

    Jerryscript 3.0.0 was discovered to contain a stack overflow via vm_loop.lto_priv.304 in /jerry-core/vm/vm.c.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2022-22891

    Last Modified: 21 Nov 2024

    Jerryscript 3.0.0 was discovered to contain a SEGV vulnerability via ecma_ref_object_inline in /jerry-core/ecma/base/ecma-gc.c.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2022-22892

    Last Modified: 21 Nov 2024

    There is an Assertion 'ecma_is_value_undefined (value) || ecma_is_value_null (value) || ecma_is_value_boolean (value) || ecma_is_value_number (value) || ecma_is_value_string (value) || ecma_is_value_bigint (value) || ecma_is_value_symbol (value) || ecma_is_value_object (value)' failed at jerry-core/ecma/base/ecma-helpers-value.c in Jerryscripts 3.0.0.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2022-22890

    Last Modified: 21 Nov 2024

    There is an Assertion 'arguments_type != SCANNER_ARGUMENTS_PRESENT && arguments_type != SCANNER_ARGUMENTS_PRESENT_NO_REG' failed at /jerry-core/parser/js/js-scanner-util.c in Jerryscript 3.0.0.

    Published: 20 Jan 2022
    7.8
    High

    CVE-2022-22888

    Last Modified: 21 Nov 2024

    Jerryscript 3.0.0 was discovered to contain a stack overflow via ecma_op_object_find_own in /ecma/operations/ecma-objects.c.

    Published: 20 Jan 2022
    7.5
    High

    CVE-2020-23315

    Last Modified: 21 Nov 2024

    There is an ASSERTION (pFuncBody->GetYieldRegister() == oldYieldRegister) failed in Js::DebugContext::RundownSourcesAndReparse in ChakraCore version 1.12.0.0-beta.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46351

    Last Modified: 21 Nov 2024

    There is an Assertion 'local_tza == ecma_date_local_time_zone_adjustment (date_value)' failed at /jerry-core/ecma/builtin-objects/ecma-builtin-date-prototype.c(ecma_builtin_date_prototype_dispatch_set):421 in JerryScript 3.0.0.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46349

    Last Modified: 21 Nov 2024

    There is an Assertion 'type == ECMA_OBJECT_TYPE_GENERAL || type == ECMA_OBJECT_TYPE_PROXY' failed at /jerry-core/ecma/operations/ecma-objects.c in JerryScript 3.0.0.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46350

    Last Modified: 21 Nov 2024

    There is an Assertion 'ecma_is_value_object (value)' failed at jerryscript/jerry-core/ecma/base/ecma-helpers-value.c in JerryScript 3.0.0.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46348

    Last Modified: 21 Nov 2024

    There is an Assertion 'ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p)' failed at /jerry-core/ecma/base/ecma-literal-storage.c in JerryScript 3.0.0.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46347

    Last Modified: 21 Nov 2024

    There is an Assertion 'ecma_object_check_class_name_is_object (obj_p)' failed at /jerry-core/ecma/operations/ecma-objects.c in JerryScript 3.0.0.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46346

    Last Modified: 21 Nov 2024

    There is an Assertion 'local_tza == ecma_date_local_time_zone_adjustment (date_value)' failed at /jerry-core/ecma/builtin-objects/ecma-builtin-date-prototype.c(ecma_builtin_date_prototype_dispatch_set):421 in JerryScript 3.0.0.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46344

    Last Modified: 21 Nov 2024

    There is an Assertion 'flags & PARSER_PATTERN_HAS_REST_ELEMENT' failed at /jerry-core/parser/js/js-parser-expr.c in JerryScript 3.0.0.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46345

    Last Modified: 21 Nov 2024

    There is an Assertion 'cesu8_cursor_p == cesu8_end_p' failed at /jerry-core/lit/lit-strings.c in JerryScript 3.0.0.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46343

    Last Modified: 21 Nov 2024

    There is an Assertion 'context_p->token.type == LEXER_LITERAL' failed at /jerry-core/parser/js/js-parser-expr.c in JerryScript 3.0.0.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46340

    Last Modified: 21 Nov 2024

    There is an Assertion 'context_p->stack_top_uint8 == SCAN_STACK_TRY_STATEMENT || context_p->stack_top_uint8 == SCAN_STACK_CATCH_STATEMENT' failed at /parser/js/js-scanner.c(scanner_scan_statement_end) in JerryScript 3.0.0.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46342

    Last Modified: 21 Nov 2024

    There is an Assertion 'ecma_is_lexical_environment (obj_p) || !ecma_op_object_is_fast_array (obj_p)' failed at /jerry-core/ecma/base/ecma-helpers.c in JerryScript 3.0.0.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46339

    Last Modified: 21 Nov 2024

    There is an Assertion 'lit_is_valid_cesu8_string (string_p, string_size)' failed at /base/ecma-helpers-string.c(ecma_new_ecma_string_from_utf8) in JerryScript 3.0.0.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46338

    Last Modified: 21 Nov 2024

    There is an Assertion 'ecma_is_lexical_environment (object_p)' failed at /base/ecma-helpers.c(ecma_get_lex_env_type) in JerryScript 3.0.0.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46337

    Last Modified: 21 Nov 2024

    There is an Assertion 'page_p != NULL' failed at /parser/js/js-parser-mem.c(parser_list_get) in JerryScript 3.0.0.

    Published: 20 Jan 2022
    7.8
    High

    CVE-2021-46334

    Last Modified: 21 Nov 2024

    Moddable SDK v11.5.0 was discovered to contain a stack buffer overflow via the component __interceptor_strcat.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46336

    Last Modified: 21 Nov 2024

    There is an Assertion 'opts & PARSER_CLASS_LITERAL_CTOR_PRESENT' failed at /parser/js/js-parser-expr.c(parser_parse_class_body) in JerryScript 3.0.0.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46335

    Last Modified: 21 Nov 2024

    Moddable SDK v11.5.0 was discovered to contain a NULL pointer dereference in the component fx_Function_prototype_hasInstance.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46333

    Last Modified: 21 Nov 2024

    Moddable SDK v11.5.0 was discovered to contain an invalid memory access vulnerability via the component __asan_memmove.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46331

    Last Modified: 21 Nov 2024

    Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsProxy.c in fxProxyGetPrototype.

    Published: 20 Jan 2022
    7.8
    High

    CVE-2021-46332

    Last Modified: 21 Nov 2024

    Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via xs/sources/xsDataView.c in fxUint8Getter.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46330

    Last Modified: 21 Nov 2024

    Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsDataView.c in fx_ArrayBuffer_prototype_concat.

    Published: 20 Jan 2022
    5.5
    Medium

    CVE-2021-46327

    Last Modified: 21 Nov 2024

    Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsArray.c in fx_Array_prototype_sort.

    Published: 20 Jan 2022
    7.8
    High

    CVE-2021-46328

    Last Modified: 21 Nov 2024

    Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via the component __libc_start_main.

    Published: 20 Jan 2022