Skip to main content

CWE archive

CWE-755 CVEs

Programmatic archive

578 CVEs tagged with CWE-75526 Critical, 261 High, 266 Medium, 25 Low, 0 Unrated.

CVE-2022-34633

Published Jul 18, 2022

CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted sfence.vma instructions rather create an exception.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32990

Published Jun 24, 2022

An issue in gimp_layer_invalidate_boundary of GNOME GIMP 2.10.30 allows attackers to trigger an unhandled exception via a crafted XCF file, causing a Denial of Service (DoS).

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1965

Published Jun 24, 2022

Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In co…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27872

Published Jun 21, 2022

A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files in Autodesk Navisworks 2022. The vulnerability exists becau…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30727

Published Jun 7, 2022

Improper handling of insufficient permissions vulnerability in addAppPackageNameToAllowList in PersonaManagerService prior to SMR Jun-2022 Release 1 allows local attackers to set…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30725

Published Jun 7, 2022

Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionError function of Bluetooth prior to SMR Jun-2022 Release 1 le…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30724

Published Jun 7, 2022

Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionCompleted function of Bluetooth prior to SMR Jun-2022 Release…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30723

Published Jun 7, 2022

Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in activateVoiceRecognitionWithDevice function of Bluetooth prior to SMR Jun-2022…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30716

Published Jun 7, 2022

Unprotected broadcast in sendIntentForToastDumpLog in DisplayToast prior to SMR Jun-2022 Release 1 allows untrusted applications to access toast message information from device.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29017

Published May 16, 2022

Bento4 v1.6.0.0 was discovered to contain a segmentation fault via the component /x86_64/multiarch/strlen-avx2.S.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20748

Published May 3, 2022

A vulnerability in the local malware analysis process of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24863

Published Apr 18, 2022

http-swagger is an open source wrapper to automatically generate RESTful API documentation with Swagger 2.0. In versions of http-swagger prior to 1.2.6 an attacker may perform a d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-40402

Published Apr 14, 2022

An out-of-bounds read vulnerability exists in the RS-274X aperture macro multiple outline primitives functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.7.1…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-0023

Published Apr 13, 2022

An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-OS software that enables a meddler-in-the-middle (MITM) to s…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25795

Published Apr 13, 2022

A Memory Corruption Vulnerability in Autodesk TrueView 2022 and 2021 may lead to remote code execution through maliciously crafted DWG files.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23161

Published Apr 12, 2022

Dell PowerScale OneFS versions 8.2.x - 9.3.0.x contain a denial-of-service vulnerability in SmartConnect. An unprivileged network attacker may potentially exploit this vulnerabili…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 251-275 of 578 CVEsPage 11 of 24