search menu icon-carat-right cmu-wordmark

CERT Coordination Center

CERT/CC Vulnerability Notes Database


Published Public Updated ID CVSS Title
2022-11-16 2022-01-10 2022-11-16 VU#709991 Netatalk contains multiple error and memory management vulnerabilities
2022-11-08 2022-11-08 2022-11-23 VU#434994 Multiple race conditions due to TOCTOU flaws in various UEFI Implementations
2022-11-01 2022-11-01 2022-12-07 VU#794340 OpenSSL 3.0.0 to 3.0.6 decodes some punycode email addresses in X.509 certificates improperly
2022-10-07 2022-10-07 2022-11-09 VU#730793 Heimdal Kerberos vulnerable to remotely triggered NULL pointer dereference
2022-10-03 2022-10-03 2022-11-10 VU#915563 Microsoft Exchange vulnerable to server-side request forgery and remote code execution.
2022-09-27 2022-09-27 2022-11-07 VU#855201 L2 network security controls can be bypassed using VLAN 0 stacking and/or 802.3 headers
2022-08-11 2022-08-11 2022-09-28 VU#309662 Signed third party UEFI bootloaders are vulnerable to Secure Boot bypass
2022-08-04 2022-08-04 2022-08-05 VU#495801 muhttpd versions 1.1.5 and earlier are vulnerable to path traversal
2022-06-21 2022-06-21 2022-06-21 VU#142546 SMA Technologies OpCon UNIX agent adds the same SSH key to all installations
2022-05-09 2022-05-02 2022-08-29 VU#473698 uClibc, uClibc-ng libraries have monotonically increasing DNS transaction ID
2022-04-28 2022-04-28 2022-04-28 VU#730007 Tychon is vulnerable to privilege escalation due to OPENSSLDIR location
2022-04-28 2010-10-10 2022-04-29 VU#411271 Qt allows for privilege escalation due to hard-coding of qt_prfxpath value
2022-03-31 2022-03-30 2022-05-19 VU#970766 Spring Framework insecurely handles PropertyDescriptor objects with data binding
2022-02-24 2022-02-24 2022-02-24 VU#383864 Visual Voice Mail (VVM) services transmit unencrypted credentials via SMS
2022-02-22 2022-02-22 2022-02-24 VU#229438 Mobile device monitoring services do not authenticate API requests

Sponsored by CISA.