Skip to main content

CWE archive

CWE-755 CVEs

Programmatic archive

585 CVEs tagged with CWE-75528 Critical, 266 High, 267 Medium, 24 Low, 0 Unrated.

CVE-2022-24863

Published Apr 18, 2022

http-swagger is an open source wrapper to automatically generate RESTful API documentation with Swagger 2.0. In versions of http-swagger prior to 1.2.6 an attacker may perform a d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-40402

Published Apr 14, 2022

An out-of-bounds read vulnerability exists in the RS-274X aperture macro multiple outline primitives functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.7.1…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-0023

Published Apr 13, 2022

An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-OS software that enables a meddler-in-the-middle (MITM) to s…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25795

Published Apr 13, 2022

A Memory Corruption Vulnerability in Autodesk TrueView 2022 and 2021 may lead to remote code execution through maliciously crafted DWG files.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23161

Published Apr 12, 2022

Dell PowerScale OneFS versions 8.2.x - 9.3.0.x contain a denial-of-service vulnerability in SmartConnect. An unprivileged network attacker may potentially exploit this vulnerabili…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27841

Published Apr 11, 2022

Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20066

Published Apr 11, 2022

In atf (hwfde), there is a possible leak of sensitive information due to incorrect error handling. This could lead to local information disclosure with System execution privileges…

CVSS 4.4 · Medium

CVE-2020-25691

Published Apr 1, 2022

A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat fro…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23625

Published Mar 11, 2022

Wire-ios is a messaging application using the wire protocol on apple's ios platform. In versions prior to 3.95 malformed resource identifiers may render the iOS Wire Client comple…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24615

Published Feb 24, 2022

zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result in an application crash. This could be used to mount a den…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21218

Published Feb 9, 2022

Uncaught exception in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22150

Published Feb 4, 2022

A memory corruption vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1.0.52543. A specially-crafted PDF document can trigger an exception w…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-0264

Published Feb 4, 2022

A vulnerability was found in the Linux kernel's eBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker wi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 585 CVEsPage 12 of 24