Snapshot
Nov. 25, 2022 - Dec. 2, 2022
CISA Known Exploited Vulnerabilities |
||||
---|---|---|---|---|
CVE | Summary | Severity | Vendor | Date Added |
CVE-2022-4135 | Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker who has compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects web browsers that utilize Chromium, including Google Chrome and Microsoft Edge. | CRITICAL | Nov. 28, 2022 | |
CVE-2021-35587 | Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product. | CRITICAL | Oracle | Nov. 28, 2022 |
Vulnerabilities In The News |
||||
CVE | Summary | Severity | Vendor | Risk Context |
CVE-2022-45483 | Lazy Mouse allows an attacker to see all data in cleartext. | N/A | Risk Context N/A | |
CVE-2022-4020 | Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privile... | HIGH | Acer | Risk Context N/A |
CVE-2022-4135 | Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the render... | CRITICAL | Microsoft, Google |
CISA Known Exploited Actively Exploited |
CVE-2022-4116 | A vulnerability was found in quarkus. | CRITICAL |
Remote Code Execution |
|
CVE-2022-36449 | An issue was discovered in the Arm Mali GPU Kernel Driver. | MEDIUM | Arm | Risk Context N/A |
CVE-2022-24521 | Windows Common Log File System Driver Elevation of Privilege Vulnerability. | HIGH | Microsoft |
CISA Known Exploited Actively Exploited Used In Ransomware |
CVE-2021-35587 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware . | CRITICAL | Oracle |
CISA Known Exploited Actively Exploited Public Exploits Available |
CVE-2021-42298 | Microsoft Defender Remote Code Execution Vulnerability | HIGH |
Actively Exploited Remote Code Execution |
CISA Known Exploited Vulnerabilities
CISA added 2 vulnerabilities to the known exploited vulnerabilities list.
Oracle — Fusion Middleware |
CVE-2021-35587 / Added: Nov. 28, 2022 |
CRITICAL CVSS 9.80 |
Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product. |
Headlines
|
In The News
Vulnerabilities receiving the most attention in traditional news media.
CVE-2022-45483 |
CVSS Not Assigned |
Risk Context N/A |
Published: Dec. 2, 2022 |
Lazy Mouse allows an attacker (in a man in the middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-4020 |
HIGH CVSS 8.20 |
Risk Context N/A |
Published: Nov. 28, 2022 |
Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secure Boot settings by modifying an NVRAM variable. |
Vendor Impacted: Acer |
Products Impacted: Extensa Ex215-21 Firmware, Aspire A315-22g, Aspire A315-22 Firmware, Aspire A115-21 Firmware, Extensa Ex215-21g, Extensa Ex215-21g Firmware, Extensa Ex215-21, Aspire A315-22, Aspire A315-22g Firmware, Aspire A115-21 |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-4135 |
CRITICAL CVSS 9.60 |
CISA Known Exploited Actively Exploited |
Published: Nov. 25, 2022 |
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) |
Vendors Impacted: Microsoft, Google |
Products Impacted: Edge Chromium, Edge, Chromium |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-4116 |
CRITICAL CVSS 9.80 |
Remote Code Execution |
Published: Nov. 22, 2022 |
A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-36449 |
MEDIUM CVSS 6.50 |
Risk Context N/A |
Published: Sept. 1, 2022 |
An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory, write a limited amount outside of buffer bounds, or to disclose details of memory mappings. This affects Midgard r4p0 through r32p0, Bifrost r0p0 through r38p0 and r39p0 before r38p1, and Valhall r19p0 through r38p0 and r39p0 before r38p1. |
Vendor Impacted: Arm |
Products Impacted: Bifrost, Valhall, Midgard |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-24521 |
HIGH CVSS 7.80 |
CISA Known Exploited Actively Exploited Used In Ransomware |
Published: April 15, 2022 |
Windows Common Log File System Driver Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-24481. |
Vendor Impacted: Microsoft |
Product Impacted: Windows |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2021-35587 |
CRITICAL CVSS 9.80 |
CISA Known Exploited Actively Exploited Public Exploits Available |
Published: Jan. 19, 2022 |
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
Vendor Impacted: Oracle |
Product Impacted: Fusion Middleware |
Quotes
|
Headlines
|
Back to top ↑ |
Accelerate Security Teams
Schedule a free consultation with a vulnerability expert to discuss your use cases and to see a demo.