Skip to main content

CWE archive

CWE-1284 CVEs

Programmatic archive

358 CVEs tagged with CWE-128422 Critical, 150 High, 158 Medium, 28 Low, 0 Unrated.

CVE-2022-41968

Published Dec 1, 2022

Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths are not validated before writing to a database. As a result,…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-4111

Published Nov 22, 2022

Unrestricted file size limit can lead to DoS in tooljet/tooljet <1.27 by allowing a logged in attacker to upload profile pictures over 2MB.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41896

Published Nov 18, 2022

TensorFlow is an open source platform for machine learning. If `ThreadUnsafeUnigramCandidateSampler` is given input `filterbank_channel_count` greater than the allowed max size, T…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36938

Published Nov 11, 2022

DexLoader function get_stringidx_fromdex() in Redex prior to commit 3b44c64 can load an out of bound address when loading the string index table, potentially allowing remote code…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-20445

Published Nov 8, 2022

In process_service_search_rsp of sdp_discovery.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with n…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39313

Published Oct 24, 2022

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.17, and prior to 5.2.8 on the 5.x branch, crash when…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2592

Published Oct 17, 2022

A lack of length validation in Snippet descriptions in GitLab CE/EE affecting all versions prior to 15.1.6, 15.2 prior to 15.2.4 and 15.3 prior to 15.3.2 allows an authenticated a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36063

Published Oct 10, 2022

Azure RTOS USBx is a USB host, device, and on-the-go (OTG) embedded stack, fully integrated with Azure RTOS ThreadX and available for all Azure RTOS ThreadX–supported processors.…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40761

Published Sep 16, 2022

The function tee_obj_free in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_AllocateOperation with a d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-20385

Published Sep 13, 2022

a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-36078

Published Sep 2, 2022

Binary provides encoding/decoding in Borsh and other formats. The vulnerability is a memory allocation vulnerability that can be exploited to allocate slices in memory with (arbit…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-21208

Published Aug 23, 2022

The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for al…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 276-300 of 358 CVEsPage 12 of 15