Search CVE reports


Toggle filters

16211 – 16220 of 44107 results

Status is adjusted based on your filters.


CVE-2022-3886

Medium priority
Ignored

Use after free in Speech Recognition in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 16.04 LTS
chromium-browser Ignored
Show less packages

CVE-2022-3885

Medium priority
Ignored

Use after free in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 16.04 LTS
chromium-browser Ignored
Show less packages

CVE-2022-23824

Medium priority
Needs evaluation

IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.

1 affected package

xen

Package 16.04 LTS
xen Needs evaluation
Show less packages

CVE-2022-39328

Medium priority
Vulnerable

Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to...

1 affected package

grafana

Package 16.04 LTS
grafana Vulnerable
Show less packages

CVE-2022-3821

Medium priority
Fixed

An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a...

1 affected package

systemd

Package 16.04 LTS
systemd Fixed
Show less packages

CVE-2022-20452

Medium priority
Ignored

In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User...

1 affected package

android-platform-frameworks-base

Package 16.04 LTS
android-platform-frameworks-base Ignored
Show less packages

CVE-2022-20448

Medium priority

Not in release

In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges...

1 affected package

android-framework-23

Package 16.04 LTS
android-framework-23 Not in release
Show less packages

CVE-2022-20446

Medium priority
Ignored

In AlwaysOnHotwordDetector of AlwaysOnHotwordDetector.java, there is a possible way to access the microphone from the background due to a missing permission check. This could lead to local escalation of privilege with...

2 affected packages

android-framework-23, android-platform-frameworks-base

Package 16.04 LTS
android-framework-23 Ignored
android-platform-frameworks-base Ignored
Show less packages

CVE-2022-39377

Medium priority
Fixed

sysstat is a set of system performance tools for the Linux operating system. On 32 bit systems, in versions 9.1.16 and newer but prior to 12.7.1, allocate_structures contains a size_t overflow in sa_common.c....

1 affected package

sysstat

Package 16.04 LTS
sysstat Fixed
Show less packages

CVE-2022-3872

Medium priority
Vulnerable

An off-by-one read/write issue was found in the SDHCI device of QEMU. It occurs when reading/writing the Buffer Data Port Register in sdhci_read_dataport and sdhci_write_dataport, respectively, if data_count == block_size. A...

1 affected package

qemu

Package 16.04 LTS
qemu Vulnerable
Show less packages