CVE-2022-1968
Use After Free in GitHub repository vim/vim prior to 8.2.
CVEs:CVE-2022-1968
Affected products
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| macos | affected | apple | — | — |
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
Use After Free in GitHub repository vim/vim prior to 8.2.
CVEs:CVE-2022-1968
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| macos | affected | apple | — | — |
A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the c...
CVEs:CVE-2022-32205
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| macos | affected | apple | — | — |
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* ...
CVEs:CVE-2022-32207
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| macos | affected | apple | — | — |
When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the client.
CVEs:CVE-2022-32208
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| macos | affected | apple | — | — |
Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
CVEs:CVE-2022-1720
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| macos | affected | apple | — | — |
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVEs:CVE-2022-2125
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| macos | affected | apple | — | — |
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
CVEs:CVE-2022-2000
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| macos | affected | apple | — | — |
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
CVEs:CVE-2022-2126
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| macos | affected | apple | — | — |
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
CVEs:CVE-2022-2124
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| macos | affected | apple | — | — |
Use After Free in GitHub repository vim/vim prior to 8.2.
CVEs:CVE-2022-2042
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| macos | affected | apple | — | — |
A program using swift-corelibs-foundation is vulnerable to a denial of service attack caused by a potentially malicious source producing a JSON document containing a type mismatch. This vulnerability is caused by the interaction between a deserializati...
CVEs:CVE-2022-1642
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| swift | affected | apple | — | — |
A vulnerability was found in Apple iPhone up to 12.4.1. It has been declared as critical. Affected by this vulnerability is Siri. Playing an audio or video file might be able to initiate Siri on the same device which makes it possible to execute comman...
CVEs:CVE-2019-25071
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| iphone_os | affected | apple | — | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.