DE EN FR
hlukh.ch MàJ : 2026-02-25T21:01:10.471Z · week: 2022-W24

Alertes de sécurité

Sélectionnées à partir d'avis publics. Objectif : visibilité, contexte et export rapide — sans clickbait.

Alertes récentes
CVE-2022-30184
.NET and Visual Studio Information Disclosure Vulnerability
2026‑02‑21 · CVE-2022-30184
MSRC 2026‑02‑21 Moyenne
CVE-2020-28493
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2020-28493
MSRC 2026‑02‑21 Moyenne
CVE-2021-22570
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2021-22570
MSRC 2026‑02‑21 Moyenne
CVE-2021-3733
<vuln:Note Title="Mariner" Type="Tag" Ordinal="20">Mariner
2026‑02‑21 · CVE-2021-3733
MSRC 2026‑02‑21 Moyenne
CVE-2022-23712
A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.
2026‑02‑21 · CVE-2022-23712
MSRC 2026‑02‑21 Élevée
CVE-2022-1943
A flaw out of bounds memory write in the Linux kernel UDF file system functionality was found in the way user triggers some file operation which triggers udf_write_fi(). A local user could use this flaw to crash the system or potentially
2026‑02‑21 · CVE-2022-1943
MSRC 2026‑02‑21 Élevée
CVE-2021-40633
A memory leak (out-of-memory) in gif2rgb in util/gif2rgb.c in giflib 5.1.4 allows remote attackers trigger an out of memory exception or denial of service via a gif format file.
2026‑02‑21 · CVE-2021-40633
MSRC 2026‑02‑21 Élevée
CVE-2022-1998
A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system.
2026‑02‑21 · CVE-2022-1998
MSRC 2026‑02‑21 Élevée
CVE-2022-27778
A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.
2026‑02‑21 · CVE-2022-27778
MSRC 2026‑02‑21 Élevée
CVE-2022-1708
A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O after command execution and it is read in a manner where the entire file corresponding to the output of the command is read in. Thus if the output of the command is large it is possible to exhaust the memory or the disk space of the node when CRI-O reads the output of the command. The highest threat from this vulnerability is system availability.
2026‑02‑21 · CVE-2022-1708
MSRC 2026‑02‑21 Élevée
CVE-2022-27775
An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.
2026‑02‑21 · CVE-2022-27775
MSRC 2026‑02‑21 Élevée
CVE-2022-27774
An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.
2026‑02‑21 · CVE-2022-27774
MSRC 2026‑02‑21 Moyenne
CVE-2022-33068
An integer overflow in the component hb-ot-shape-fallback.cc of Harfbuzz v4.3.0 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
2026‑02‑21 · CVE-2022-33068
MSRC 2026‑02‑21 Moyenne
CVE-2022-32981
An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in ptrace PEEKUSER and POKEUSER (aka PEEKUSR and POKEUSR) when accessing floating point registers.
2026‑02‑21 · CVE-2022-32981
MSRC 2026‑02‑21 Élevée
CVE-2022-1996
Authorization Bypass Through User-Controlled Key in emicklei/go-restful
2026‑02‑21 · CVE-2022-1996
MSRC 2026‑02‑21 Critique
CVE-2022-30167
AV1 Video Extension Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2022-30167
MSRC 2026‑02‑21 Élevée
CVE-2022-30193
AV1 Video Extension Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2022-30193
MSRC 2026‑02‑21 Élevée
CVE-2022-30180
Azure RTOS GUIX Studio Information Disclosure Vulnerability
2026‑02‑21 · CVE-2022-30180
MSRC 2026‑02‑21 Élevée
CVE-2022-30177
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2022-30177
MSRC 2026‑02‑21 Élevée
CVE-2022-30178
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2022-30178
MSRC 2026‑02‑21 Élevée
CVE-2022-30179
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2022-30179
MSRC 2026‑02‑21 Élevée
CVE-2022-30137
Azure Service Fabric Container Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2022-30137
MSRC 2026‑02‑21 Moyenne
CVE-2022-2175
Buffer Over-read in vim/vim
2026‑02‑21 · CVE-2022-2175
MSRC 2026‑02‑21 Élevée
CVE-2022-2124
Buffer Over-read in vim/vim
2026‑02‑21 · CVE-2022-2124
MSRC 2026‑02‑21 Élevée
CVE-2022-31030
containerd CRI plugin: Host memory exhaustion through ExecSync
2026‑02‑21 · CVE-2022-31030
MSRC 2026‑02‑21 Moyenne
CVE-2022-30790
Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
2026‑02‑21 · CVE-2022-30790
MSRC 2026‑02‑21 Élevée
CVE-2022-30552
Das U-Boot 2022.01 has a Buffer Overflow.
2026‑02‑21 · CVE-2022-30552
MSRC 2026‑02‑21 Moyenne
CVE-2022-25345
Denial of Service (DoS)
2026‑02‑21 · CVE-2022-25345
MSRC 2026‑02‑21 Élevée
CVE-2022-33981
drivers/block/floppy.c in the Linux kernel before 5.17.6 is vulnerable to a denial of service because of a concurrency use-after-free flaw after deallocating raw_cmd in the raw_cmd_ioctl function.
2026‑02‑21 · CVE-2022-33981
MSRC 2026‑02‑21 Faible
CVE-2022-31625
Freeing unallocated memory in php_pgsql_free_params()
2026‑02‑21 · CVE-2022-31625
MSRC 2026‑02‑21 Élevée
CVE-2022-29526
Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter the Faccessat function could incorrectly report that a file is accessible.
2026‑02‑21 · CVE-2022-29526
MSRC 2026‑02‑21 Moyenne
CVE-2022-2182
Heap-based Buffer Overflow in vim/vim
2026‑02‑21 · CVE-2022-2182
MSRC 2026‑02‑21 Élevée
CVE-2022-2125
Heap-based Buffer Overflow in vim/vim
2026‑02‑21 · CVE-2022-2125
MSRC 2026‑02‑21 Élevée
CVE-2022-29119
HEVC Video Extensions Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2022-29119
MSRC 2026‑02‑21 Élevée
CVE-2022-22018
HEVC Video Extensions Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2022-22018
MSRC 2026‑02‑21 Élevée
CVE-2022-29111
HEVC Video Extensions Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2022-29111
MSRC 2026‑02‑21 Élevée
CVE-2022-30188
HEVC Video Extensions Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2022-30188
MSRC 2026‑02‑21 Élevée
CVE-2022-34835
In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the corruption of the return address pointer of the do_i2c_md function.
2026‑02‑21 · CVE-2022-34835
MSRC 2026‑02‑21 Critique
CVE-2022-34176
Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.
2026‑02‑21 · CVE-2022-34176
MSRC 2026‑02‑21 Moyenne
CVE-2022-30164
Kerberos AppContainer Security Feature Bypass Vulnerability
2026‑02‑21 · CVE-2022-30164
MSRC 2026‑02‑21 Élevée
CVE-2022-27781
libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function a malicious server could make libcurl built withNSS get stuck in a never-ending busy-loop when trying to retrieve thatinformation.
2026‑02‑21 · CVE-2022-27781
MSRC 2026‑02‑21 Élevée
CVE-2022-27782
libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However several TLS andSSH settings were left out from the configuration match checks making themmatch too easily.
2026‑02‑21 · CVE-2022-27782
MSRC 2026‑02‑21 Élevée
CVE-2022-27779
libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie engine" can bebuilt with or without [Public Suffix List](https://publicsuffix.org/)awareness. If PSL support not provided a more rudimentary check exists to atleast prevent cookies from being set on TLDs. This check was broken if thehost name in the URL uses a trailing dot.This can allow arbitrary sites to set cookies that then would get sent to adifferent and unrelated site or domain.
2026‑02‑21 · CVE-2022-27779
MSRC 2026‑02‑21 Moyenne
CVE-2022-30166
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2022-30166
MSRC 2026‑02‑21 Élevée
CVE-2022-30192
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2022-30192
MSRC 2026‑02‑21 Élevée
CVE-2022-33638
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2022-33638
MSRC 2026‑02‑21 Élevée
CVE-2022-33639
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2022-33639
MSRC 2026‑02‑21 Élevée
CVE-2022-33680
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
2026‑02‑21 · CVE-2022-33680
MSRC 2026‑02‑21 Élevée
CVE-2022-22021
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2022-22021
MSRC 2026‑02‑21 Élevée
CVE-2022-30173
Microsoft Excel Remote Code Execution Vulnerability
2026‑02‑21 · CVE-2022-30173
MSRC 2026‑02‑21 Élevée
Page 1