CVEs from 2022

8,004 normalized CVEs published or assigned in this year.

Total
8,004
critical
critical 88
high
high 1,240
medium
medium 887
low
low 23
% Critical
1.1%
% with KEV
1.6%
% with exploit
1.6%

Top vendors

Top products

  • jdk 116
  • jre 109
  • openjdk 100
  • zulu 82
  • graalvm 74
  • cloud_secure_agent 35
  • oncommand_insight 34
  • cloud_insights_acquisition_unit 34
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2022-28356 high 8.0 In the Linux kernel before 5.17.1, a refcount leak bug was found in net/llc/af_llc.c. archsusedebian
CVE-2022-47940 high 8.0 An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.18 before 5.18.18. fs/ksmbd/smb2pdu.c lacks length validation in the non-padding case in smb2_write. archdebiansuse
CVE-2022-1015 high 8.0 A flaw was found in the Linux kernel in linux/net/netfilter/nf_tables_api.c of the netfilter subsystem. This flaw allows a local user to cause an out-of-bounds write issue. archsusedebian
CVE-2022-1199 high 8.0 A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-aft… archsusedebian
CVE-2022-1198 high 8.0 A use-after-free vulnerabilitity was discovered in drivers/net/hamradio/6pack.c of linux that allows an attacker to crash linux kernel by simulating ax25 device using 6pack driver from user space. archsusedebian
CVE-2022-3544 high 8.0 A vulnerability, which was classified as problematic, was found in Linux Kernel. Affected is the function damon_sysfs_add_target of the file mm/damon/sysfs.c of the component Netfilter. The manipulat… archsusedebian
CVE-2022-1433 high 8.0 multiple issues in gitlab arch
CVE-2022-1205 high 8.0 A NULL pointer dereference flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a user connects with the protocol. This flaw allows a local user to crash the sys… archsusedebian
CVE-2022-3646 high 8.0 A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function nilfs_attach_log_writer of the file fs/nilfs2/segment.c of the component BPF. The… archsusedebian
CVE-2022-1516 high 8.0 A NULL pointer dereference flaw was found in the Linux kernel’s X.25 set of standardized network protocols functionality in the way a user terminates their session using a simulated Ethernet card and… archsusedebian
CVE-2022-47946 high 8.0 An issue was discovered in the Linux kernel 5.10.x before 5.10.155. A use-after-free in io_sqpoll_wait_sq in fs/io_uring.c allows an attacker to crash the kernel, resulting in denial of service. fini… archdebiansuse
CVE-2022-47941 high 8.0 An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c omits a kfree call in certain smb2_handle_negotiate error conditions, aka a memory leak. archdebiansuse
CVE-2022-39842 high 8.0 An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer over… archsusedebian
CVE-2022-1635 high 8.0 Use after free in Permission Prompts in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruptio… archdebian
CVE-2022-4382 high 8.0 A use-after-free flaw caused by a race among the superblock operations in the gadgetfs Linux driver was found. It could be triggered by yanking out a device that is running the gadgetfs side. archsusedebian
CVE-2022-1638 high 8.0 Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2022-47939 high 8.0 An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c has a use-after-free and OOPS for SMB2_TREE_DISCONNECT. archdebiansuse
CVE-2022-1636 high 8.0 Use after free in Performance APIs in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2022-1633 high 8.0 Use after free in Sharesheet in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corr… archdebian
CVE-2022-40307 high 8.0 An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition with a resultant use-after-free. archsusedebian
CVE-2022-3586 high 8.0 A flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue function used the socket buffer (SKB) cb field after the same SKB had been enqueued (… archsusedebian
CVE-2022-3541 high 8.0 A vulnerability classified as critical has been found in Linux Kernel. This affects the function spl2sw_nvmem_get_mac_address of the file drivers/net/ethernet/sunplus/spl2sw_driver.c of the component… archdebian
CVE-2022-3621 high 8.0 A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_bmap_lookup_at_level of the file fs/nilfs2/inode.c of the component nilfs2. The manipu… archsusedebian
CVE-2022-31743 high 8.0 Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to escape HTML comments on pages that put user-controll… archdebian
CVE-2022-1406 high 8.0 multiple issues in gitlab arch
CVE-2022-1352 high 8.0 multiple issues in gitlab arch
CVE-2022-1919 high 8.0 Use after free in Codecs in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. archdebian
CVE-2022-1124 high 8.0 multiple issues in gitlab arch
CVE-2022-0812 high 8.0 An information leak flaw was found in NFS over RDMA in the net/sunrpc/xprtrdma/rpc_rdma.c in the Linux Kernel. This flaw allows an attacker with normal user privileges to leak kernel information. archsusedebian
CVE-2022-1634 high 8.0 Use after free in Browser UI in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who had convinced a user to engage in specific UI interaction to potentially exploit heap corruption via… archdebian
CVE-2022-29582 high 8.0 In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; howe… archsusedebian
CVE-2022-1428 high 8.0 multiple issues in gitlab arch
CVE-2022-26385 high 8.0 In unusual circumstances, an individual thread may outlive the thread's manager during shutdown. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability af… archdebian
CVE-2022-2318 high 8.0 There are use-after-free vulnerabilities caused by timer handler in net/rose/rose_timer.c of linux that allow attackers to crash linux kernel without any privileges. archsusedebian
CVE-2022-1431 high 8.0 multiple issues in gitlab arch
CVE-2022-26981 high 8.0 Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c). archsusedebian
CVE-2022-29536 high 8.0 In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because th… archdebian
CVE-2022-1510 high 8.0 multiple issues in gitlab arch
CVE-2022-29915 high 8.0 The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This vulnerability affects Firefox < 100. archdebian
CVE-2022-1423 high 8.0 multiple issues in gitlab arch
CVE-2022-1417 high 8.0 multiple issues in gitlab arch
CVE-2022-30294 high 8.0 arbitrary code execution in wpewebkit archsuse
CVE-2022-20785 high 8.0 On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in HTML file parser of Clam AntiVirus… archdebiansuse
CVE-2022-1460 high 8.0 multiple issues in gitlab arch
CVE-2022-32744 high 8.0 A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpasswd requests with its own key, a user can change other users' passwords, enabl… archsusedebian
CVE-2022-1416 high 8.0 multiple issues in gitlab arch
CVE-2022-1637 high 8.0 Inappropriate implementation in Web Contents in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to leak cross-origin data via a crafted HTML page. archdebian
CVE-2022-2031 high 8.0 A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets. A user who has bee… archsusedebian
CVE-2022-3977 high 8.0 A use-after-free flaw was found in the Linux kernel MCTP (Management Component Transport Protocol) functionality. This issue occurs when a user simultaneously calls DROPTAG ioctl and socket close hap… archsusedebian
CVE-2022-3635 high 8.0 A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this issue is the function tst_timer of the file drivers/atm/idt77252.c of the component IPsec. The mani… archsusedebian
CVE-2022-1426 high 8.0 multiple issues in gitlab arch
CVE-2022-0667 high 8.0 When the vulnerability is triggered the BIND process will exit. BIND 9.18.0 debianarchsuse
CVE-2022-4130 high 8.0 Important: Satellite 6.14 security and bug fix update rockylinux
CVE-2022-1975 high 8.0 There is a sleep-in-atomic bug in /net/nfc/netlink.c that allows an attacker to crash the Linux kernel by simulating a nfc device from user-space. archsusedebian
CVE-2022-1734 high 8.0 A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware dow… archsusedebian
CVE-2022-2978 high 8.0 A flaw use after free in the Linux kernel NILFS file system was found in the way user triggers function security_inode_alloc to fail with following call to function nilfs_mdt_destroy. A local user co… archsusedebian
CVE-2022-3543 high 8.0 A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function unix_sock_destructor/unix_release_sock of the file net/unix/af_unix.c of the comp… archdebian
CVE-2022-3061 high 8.0 Found Linux Kernel flaw in the i740 driver. The Userspace program could pass any values to the driver through ioctl() interface. The driver doesn't check the value of 'pixclock', so it may cause a di… archsusedebian
CVE-2022-1640 high 8.0 Use after free in Sharing in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a cra… archdebian
CVE-2022-49846 high 8.0 11mo ago Important: kernel-rt security update redhatsusedebian
CVE-2022-49043 high 8.0 1y ago Important: libxml2 security update redhatrockylinuxsusedebian
CVE-2022-24834 high 8.0 1y ago Important: redis security update redhatrockylinuxsusedebian
CVE-2022-36021 high 8.0 1y ago Important: redis:6 security update rockylinuxsusedebian
CVE-2022-35977 high 8.0 1y ago Important: redis:6 security update rockylinuxsusedebian
CVE-2022-48804 high 8.0 2y ago Important: kernel security update redhatrockylinuxsusedebian+1
CVE-2022-48760 high 8.0 2y ago Important: kernel security update rockylinuxsusedebianalmalinux
CVE-2022-48836 high 8.0 2y ago Important: kernel security update rockylinuxsusedebianalmalinux
CVE-2022-48619 high 8.0 2y ago Important: kernel security update rockylinuxdebiansusealmalinux
CVE-2022-48754 high 8.0 2y ago Important: kernel security update rockylinuxsusedebianalmalinux
CVE-2022-48747 high 8.0 2y ago Important: kernel security update rockylinuxsusedebian
CVE-2022-48757 high 8.0 2y ago Important: kernel security update rockylinuxsusedebian
CVE-2022-48743 high 8.0 2y ago Important: kernel security update redhatrockylinuxsusedebian
CVE-2022-36765 high 8.0 2y ago Important: edk2 security update redhatdebiansuse
CVE-2022-49011 high 8.0 2y ago Important: kernel-rt security update redhatsusedebian
CVE-2022-36764 high 8.0 2y ago Important: edk2 security update redhatdebiansuserockylinux
CVE-2022-50637 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: cpufreq: qcom-hw: Fix memory leak in qcom_cpufreq_hw_read_lut() If "cpu_dev" fails to get opp table in qcom_cpufreq_hw_read_lut()… redhatsusedebian
CVE-2022-49744 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: mm/uffd: fix pte marker when fork() without fork event Patch series "mm: Fixes on pte markers". Patch 1 resolves the syzkiller r… redhatsusedebian
CVE-2022-49721 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: arm64: ftrace: consistently handle PLTs. Sometimes it is necessary to use a PLT entry to call an ftrace trampoline. This is handl… redhatsusedebian
CVE-2022-50845 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: ext4: fix inode leak in ext4_xattr_inode_create() on an error path There is issue as follows when do setxattr with inject fault: … redhatsusedebian
CVE-2022-0480 high 8.0 2y ago Important: kernel security, bug fix, and enhancement update redhatsusedebian
CVE-2022-49940 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: add sanity check for gsm->receive in gsm_receive_buf() A null pointer dereference can happen when attempting to acces… redhatsusedebian
CVE-2022-49754 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix a buffer overflow in mgmt_mesh_add() Smatch Warning: net/bluetooth/mgmt_util.c:375 mgmt_mesh_add() error: __memcpy… redhatsusedebian
CVE-2022-50447 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix crash on hci_create_cis_sync When attempting to connect multiple ISO sockets without using DEFER_SETUP m… redhatsusedebian
CVE-2022-50313 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: erofs: fix order >= MAX_ORDER warning due to crafted negative i_size As syzbot reported [1], the root cause is that i_size field … redhatsusedebian
CVE-2022-49322 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: tracing: Fix sleeping function called from invalid context on RT kernel When setting bootparams="trace_event=initcall:initcall_st… redhatsusedebian
CVE-2022-48632 high 8.0 2y ago Important: kernel security update redhatrockylinuxdebiansuse
CVE-2022-50780 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: net: fix UAF issue in nfqnl_nf_hook_drop() when ops_init() failed When the ops_init() interface is invoked to initialize the net,… redhatsusedebian
CVE-2022-50879 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: objtool: Fix SEGFAULT find_insn() will return NULL in case of failure. Check insn in order to avoid a kernel Oops for NULL pointe… redhatsusedebian
CVE-2022-49350 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: net: mdio: unexport __init-annotated mdio_bus_init() EXPORT_SYMBOL and __init is a bad combination because the .init.text section… redhatsusedebian
CVE-2022-50485 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: ext4: add EXT4_IGET_BAD flag to prevent unexpected bad inode There are many places that will get unhappy (and crash) when ext4_ig… redhatsusedebian
CVE-2022-50286 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: ext4: fix delayed allocation bug in ext4_clu_mapped for bigalloc + inline When converting files with inline data to extents, dela… redhatsusedebian
CVE-2022-50777 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_device() return device node with refcount incremented… redhatsusedebian
CVE-2022-50080 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: tee: add overflow check in register_shm_helper() With special lengths supplied by user space, register_shm_helper() has an intege… redhatsusedebian
CVE-2022-50638 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: ext4: fix bug_on in __es_tree_search caused by bad boot loader inode We got a issue as fllows: ==================================… redhatsusedebian
CVE-2022-50782 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: ext4: fix bug_on in __es_tree_search caused by bad quota inode We got a issue as fllows: ========================================… redhatsusedebian
CVE-2022-50277 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: ext4: don't allow journal inode to have encrypt flag Mounting a filesystem whose journal inode has the encrypt flag causes a NULL… redhatsusedebian
CVE-2022-50374 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_{ldisc,serdev}: check percpu_init_rwsem() failure syzbot is reporting NULL pointer dereference at hci_uart_tty_clo… redhatsusedebian
CVE-2022-50642 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_typec: zero out stale pointers `cros_typec_get_switch_handles` allocates four pointers when obtaining ty… redhatsusedebian
CVE-2022-50736 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix immediate work request flush to completion queue Correctly set send queue element opcode during immediate work requ… redhatsusedebian
CVE-2022-50202 high 8.0 2y ago In the Linux kernel, the following vulnerability has been resolved: PM: hibernate: defer device probing when resuming from hibernation syzbot is reporting hung task at misc_open() [1], for there is… redhatsusedebian