Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-44177 | 1 Tenda | 2 Ac18, Ac18 Firmware | 2022-11-28 | N/A | 9.8 CRITICAL |
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formWifiWpsStart. | |||||
CVE-2022-44176 | 1 Tenda | 2 Ac18, Ac18 Firmware | 2022-11-28 | N/A | 9.8 CRITICAL |
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic. | |||||
CVE-2022-44175 | 1 Tenda | 2 Ac18, Ac18 Firmware | 2022-11-28 | N/A | 9.8 CRITICAL |
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetMacFilterCfg. | |||||
CVE-2022-44174 | 1 Tenda | 2 Ac18, Ac18 Firmware | 2022-11-28 | N/A | 9.8 CRITICAL |
Tenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName. | |||||
CVE-2022-44172 | 1 Tenda | 2 Ac18, Ac18 Firmware | 2022-11-28 | N/A | 9.8 CRITICAL |
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function R7WebsSecurityHandler. | |||||
CVE-2022-44171 | 1 Tenda | 2 Ac18, Ac18 Firmware | 2022-11-28 | N/A | 9.8 CRITICAL |
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function form_fast_setting_wifi_set. | |||||
CVE-2022-4066 | 2 Mozilla, Onion Project | 2 Firefox, Onion | 2022-11-28 | N/A | 8.2 HIGH |
A vulnerability was found in davidmoreno onion. It has been rated as problematic. Affected by this issue is the function onion_response_flush of the file src/onion/response.c of the component Log Handler. The manipulation leads to allocation of resources. The name of the patch is de8ea938342b36c28024fd8393ebc27b8442a161. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-214028. | |||||
CVE-2022-44183 | 1 Tenda | 2 Ac18, Ac18 Firmware | 2022-11-28 | N/A | 9.8 CRITICAL |
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic. | |||||
CVE-2022-36111 | 1 Codenotary | 1 Immudb | 2022-11-26 | N/A | 5.3 MEDIUM |
immudb is a database with built-in cryptographic proof and verification. In versions prior to 1.4.1, a malicious immudb server can provide a falsified proof that will be accepted by the client SDK signing a falsified transaction replacing the genuine one. This situation can not be triggered by a genuine immudb server and requires the client to perform a specific list of verified operations resulting in acceptance of an invalid state value. This vulnerability only affects immudb client SDKs, the immudb server itself is not affected by this vulnerability. This issue has been patched in version 1.4.1. | |||||
CVE-2022-34830 | 1 Arm | 1 Utgard Gpu Kernel Driver | 2022-11-26 | N/A | 7.5 HIGH |
An Arm product family through 2022-06-29 has a TOCTOU Race Condition that allows non-privileged user to make improper GPU processing operations to gain access to already freed memory. | |||||
CVE-2022-37772 | 1 Maarch | 1 Maarch Rm | 2022-11-26 | N/A | 7.5 HIGH |
Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the application. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to compromised accounts. | |||||
CVE-2022-44260 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2022-11-25 | N/A | 8.8 HIGH |
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter sPort/ePort in the setIpPortFilterRules function. | |||||
CVE-2022-44259 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2022-11-25 | N/A | 8.8 HIGH |
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTime in the setParentalRules function. | |||||
CVE-2022-44258 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2022-11-25 | N/A | 8.8 HIGH |
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTracerouteCfg function. | |||||
CVE-2022-44257 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2022-11-25 | N/A | 8.8 HIGH |
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function. | |||||
CVE-2022-44256 | 1 Totolink | 2 Nr1800x, Nr1800x Firmware | 2022-11-25 | N/A | 8.8 HIGH |
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLanguageCfg function. | |||||
CVE-2022-44255 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2022-11-25 | N/A | 9.8 CRITICAL |
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post data. | |||||
CVE-2022-44254 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2022-11-25 | N/A | 8.8 HIGH |
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg function. | |||||
CVE-2022-44253 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2022-11-25 | N/A | 8.8 HIGH |
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosisCfg function. | |||||
CVE-2022-44252 | 1 Totolink | 2 Lr350, Lr350 Firmware | 2022-11-25 | N/A | 9.8 CRITICAL |
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function. |