2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1401HIGH7.5Improper Access Control vulnerability in the /Exago/WrImageResource.adx route as used in Device42 Asset Management Appli...
CVE-2022-1400CRITICAL9.8Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42...
CVE-2022-1399CRITICAL9.1An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery compo...
CVE-2022-25799MEDIUM6.1An open redirect vulnerability exists in CERT/CC VINCE software prior to 1.50.0. An attacker could send a link that has ...
CVE-2022-38238HIGH7.8XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::lookChar() at /xpdf/Stream.cc.
CVE-2022-38237HIGH7.8XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::readScan() at /xpdf/Stream.cc.
CVE-2022-38236HIGH7.8XPDF commit ffaf11c was discovered to contain a global-buffer overflow via Lexer::getObj(Object*) at /xpdf/Lexer.cc.
CVE-2022-38235MEDIUM5.5XPDF commit ffaf11c was discovered to contain a segmentation violation via DCTStream::getChar() at /xpdf/Stream.cc.
CVE-2022-38234MEDIUM5.5XPDF commit ffaf11c was discovered to contain a segmentation violation via Lexer::getObj(Object*) at /xpdf/Lexer.cc.
CVE-2022-38233MEDIUM5.5XPDF commit ffaf11c was discovered to contain a segmentation violation via DCTStream::readMCURow() at /xpdf/Stream.cc.
CVE-2022-38231HIGH7.8XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::getChar() at /xpdf/Stream.cc.
CVE-2022-38230MEDIUM5.5XPDF commit ffaf11c was discovered to contain a floating point exception (FPE) via DCTStream::decodeImage() at /xpdf/Str...
CVE-2022-38229HIGH7.8XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/...
CVE-2022-38228HIGH7.8XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::transformDataUnit at /xpdf/Stream.cc...
CVE-2022-38227HIGH7.8XPDF commit ffaf11c was discovered to contain a stack overflow via __asan_memcpy at asan_interceptors_memintrinsics.cpp.
CVE-2022-37781HIGH7.8fdkaac v1.0.3 was discovered to contain a heap buffer overflow via __interceptor_memcpy.part.46 at /sanitizer_common/san...
CVE-2022-37439MEDIUM5.5In Splunk Enterprise and Universal Forwarder versions in the following table, indexing a specially crafted ZIP file usin...
CVE-2022-37438LOW3.5In Splunk Enterprise versions in the following table, an authenticated user can craft a dashboard that could potentially...
CVE-2022-37437CRITICAL9.8When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, T...
CVE-2022-36155MEDIUM5.5tifig v0.2.2 was discovered to contain a resource allocation issue via operator new(unsigned long) at asan_new_delete.cp...
CVE-2022-36153MEDIUM5.5tifig v0.2.2 was discovered to contain a segmentation violation via std::vector<unsigned int, std::allocator<unsigned in...
CVE-2022-36152MEDIUM5.5tifig v0.2.2 was discovered to contain a memory leak via operator new[](unsigned long) at /asan/asan_new_delete.cpp.
CVE-2022-36151MEDIUM5.5tifig v0.2.2 was discovered to contain a segmentation violation via getType() at /common/bbox.cpp.
CVE-2022-36150MEDIUM5.5tifig v0.2.2 was discovered to contain a heap-buffer overflow via __asan_memmove at /asan/asan_interceptors_memintrinsic...
CVE-2022-36149MEDIUM5.5tifig v0.2.2 was discovered to contain a heap-use-after-free via temInfoEntry().

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now