We have compiled a list of Security Vulnerabilities that were discovered in February 2022. We are available to assist you if you need help applying or investigating these vulnerabilities.
Google Chrome Vulnerabilities
CVE Number | Date of Release | Severity | Description |
CVE-2022-0311 | 12/02/22 | 6.8 | Heap buffer overflow in Task Manager in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-0310 | 12/02/22 | 6.8 | Heap buffer overflow in Task Manager in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via specific user interactions. |
CVE-2022-0307 | 12/02/22 | 6.8 | Use after free in Optimization Guide in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-0306 | 12/02/22 | 6.8 | Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-0304 | 12/02/22 | 6.8 | Use after free in Bookmarks in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-0302 | 12/02/22 | 6.8 | Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed an attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-0301 | 12/02/22 | 6.8 | Heap buffer overflow in DevTools in Google Chrome prior to 97.0.4692.99 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-0298 | 12/02/22 | 6.8 | Use after free in Scheduling in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-0297 | 12/02/22 | 6.8 | Use after free in Vulkan in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-0296 | 12/02/22 | 6.8 | Use after free in Printing in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced the user to engage is specific user interactions to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-0295 | 12/02/22 | 6.8 | Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced the user to engage is specific user interactions to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-0293 | 12/02/22 | 6.8 | Use after free in Web packaging in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-0290 | 12/02/22 | 6.8 | Use after free in Site isolation in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. |
CVE-2022-0289 | 12/02/22 | 6.8 | Use after free in Safe browsing in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-0115 | 12/02/22 | 6.8 | Uninitialized use in File API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. |
CVE-2022-0114 | 12/02/22 | 5.8 | Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page and virtual serial port driver. |
CVE-2022-0107 | 12/02/22 | 6.8 | Use after free in File Manager API in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-0106 | 12/02/22 | 6.8 | Use after free in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-0105 | 12/02/22 | 6.8 | Use after free in PDF Accessibility in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-0104 | 12/02/22 | 6.8 | Heap buffer overflow in ANGLE in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-0103 | 12/02/22 | 6.8 | Use after free in SwiftShader in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-0102 | 12/02/22 | 6.8 | Type confusion in V8 in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-0101 | 12/02/22 | 6.8 | Heap buffer overflow in Bookmarks in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to potentially exploit heap corruption via specific user gesture. |
CVE-2022-0100 | 12/02/22 | 6.8 | Heap buffer overflow in Media streams API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2022-0099 | 12/02/22 | 6.8 | Use after free in Sign-in in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gestures to potentially exploit heap corruption via specific user gesture. |
CVE-2022-0098 | 12/02/22 | 6.8 | Use after free in Screen Capture in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to perform specific user gestures to potentially exploit heap corruption via specific user gestures. |
CVE-2022-0097 | 12/02/22 | 6.8 | Inappropriate implementation in DevTools in Google Chrome prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to to potentially allow extension to escape the sandbox via a crafted HTML page. |
CVE-2022-0096 | 12/02/22 | 6.8 | Use after free in Storage in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-4102 | 11/02/22 | 6.8 | Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-4101 | 11/02/22 | 6.8 | Heap buffer overflow in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-4100 | 11/02/22 | 6.8 | Object lifecycle issue in ANGLE in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
CVE-2021-4099 | 11/02/22 | 6.8 | Use after free in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
SUSE Linux Enterprise Server Vulnerabilities
CVE Number | Date of Release | Severity | Description |
CVE-2021-45082 | 19/02/22 | 4.6 | An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the “#from MODULE import” substring. (Only lines beginning with #import are blocked.) |
RedHat Enterprise Linux Vulnerabilities
CVE Number | Date of Release | Severity | Description |
CVE-2022-0530 | 09/02/22 | 6.8 | A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution. |
CVE-2022-0529 | 09/02/22 | 6.8 | A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution. |
CVE-2021-44142 | 21/02/22 | 9 | The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide “…enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver.” Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root. |
CVE-2021-26252 | 24/02/22 | 6.8 | A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service. |
CVE-2021-20325 | 18/02/22 | 10 | Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-2021-20325 was assigned to that Red Hat specific security regression and it does not affect the upstream versions of httpd. |
CVE-2021-4154 | 04/02/22 | 7.2 | A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel’s cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system. |
CVE-2021-4093 | 18/02/22 | 7.2 | A flaw was found in the KVM’s AMD code for supporting the Secure Encrypted Virtualization-Encrypted State (SEV-ES). A KVM guest using SEV-ES can trigger out-of-bounds reads and writes in the host kernel via a malicious VMGEXIT for a string I/O instruction (for example, outs or ins) using the exit reason SVM_EXIT_IOIO. This issue results in a crash of the entire system or a potential guest-to-host escape scenario. |
CVE-2021-3773 | 16/02/22 | 7.5 | A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks. |
CVE-2021-3752 | 16/02/22 | 7.9 | A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. |
CVE-2021-3657 | 18/02/22 | 7.5 | A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution. |
CVE-2021-3610 | 24/02/22 | 5 | A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault. |
CVE-2021-3578 | 16/02/22 | 7.2 | A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the client. |
CVE-2020-25719 | 18/02/22 | 9 | A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerberos PAC and always use the SIDs found within. The result could include total domain compromise. |
CVE-2020-25717 | 18/02/22 | 8.5 | A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation. |
Windows 10 Vulnerabilities
CVE Number | Date of Release | Severity | Description |
CVE-2022-22718 | 09/02/22 | 7.2 | Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21997, CVE-2022-21999, CVE-2022-22717. |
CVE-2022-22717 | 09/02/22 | 6.9 | Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21997, CVE-2022-21999, CVE-2022-22718. |
CVE-2022-22715 | 09/02/22 | 7.2 | Named Pipe File System Elevation of Privilege Vulnerability. |
CVE-2022-22001 | 09/02/22 | 7.2 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability. |
CVE-2022-22000 | 09/02/22 | 7.2 | Windows Common Log File System Driver Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21981. |
CVE-2022-21995 | 09/02/22 | 6.8 | Windows Hyper-V Remote Code Execution Vulnerability. |
CVE-2022-21994 | 09/02/22 | 7.2 | Windows DWM Core Library Elevation of Privilege Vulnerability. |
CVE-2022-21993 | 09/02/22 | 7.8 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability. |
CVE-2022-21992 | 09/02/22 | 9.3 | Windows Mobile Device Management Remote Code Execution Vulnerability. |
CVE-2022-21989 | 09/02/22 | 6.9 | Windows Kernel Elevation of Privilege Vulnerability. |
CVE-2022-21984 | 09/02/22 | 6 | Windows DNS Server Remote Code Execution Vulnerability. |
CVE-2022-21974 | 09/02/22 | 9.3 | Roaming Security Rights Management Services Remote Code Execution Vulnerability. |
CVE-2022-21971 | 09/02/22 | 9.3 | Windows Runtime Remote Code Execution Vulnerability. |
Windows 11 Vulnerabilities
CVE Number | Date of Release | Severity | Description |
CVE-2022-22718 | 09/02/22 | 7.2 | Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21997, CVE-2022-21999, CVE-2022-22717. |
CVE-2022-22717 | 09/02/22 | 6.9 | Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21997, CVE-2022-21999, CVE-2022-22718. |
CVE-2022-22715 | 09/02/22 | 7.2 | Named Pipe File System Elevation of Privilege Vulnerability. |
CVE-2022-22001 | 09/02/22 | 7.2 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability. |
CVE-2022-22000 | 09/02/22 | 7.2 | Windows Common Log File System Driver Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21981. |
CVE-2022-21996 | 09/02/22 | 7.2 | Win32k Elevation of Privilege Vulnerability. |
CVE-2022-21995 | 09/02/22 | 6.8 | Windows Hyper-V Remote Code Execution Vulnerability. |
CVE-2022-21994 | 09/02/22 | 7.2 | Windows DWM Core Library Elevation of Privilege Vulnerability. |
CVE-2022-21993 | 09/02/22 | 7.8 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability. |
CVE-2022-21992 | 09/02/22 | 9.3 | Windows Mobile Device Management Remote Code Execution Vulnerability. |
CVE-2022-21989 | 09/02/22 | 6.9 | Windows Kernel Elevation of Privilege Vulnerability. |
CVE-2022-21984 | 09/02/22 | 6 | Windows DNS Server Remote Code Execution Vulnerability. |
CVE-2022-21974 | 09/02/22 | 9.3 | Roaming Security Rights Management Services Remote Code Execution Vulnerability. |
CVE-2022-21971 | 09/02/22 | 9.3 | Windows Runtime Remote Code Execution Vulnerability. |
Windows Server 2012 Vulnerabilities
CVE Number | Date of Release | Severity | Description |
CVE-2022-22718 | 09/02/22 | 7.2 | Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21997, CVE-2022-21999, CVE-2022-22717. |
CVE-2022-22717 | 09/02/22 | 6.9 | Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21997, CVE-2022-21999, CVE-2022-22718. |
CVE-2022-22001 | 09/02/22 | 7.2 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability. |
CVE-2022-22000 | 09/02/22 | 7.2 | Windows Common Log File System Driver Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21981. |
CVE-2022-21993 | 09/02/22 | 7.8 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability. |
CVE-2022-21989 | 09/02/22 | 6.9 | Windows Kernel Elevation of Privilege Vulnerability. |
Windows Server 2016 Vulnerabilities
CVE Number | Date of Release | Severity | Description |
CVE-2022-22718 | 09/02/22 | 7.2 | Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21997, CVE-2022-21999, CVE-2022-22717. |
CVE-2022-22717 | 09/02/22 | 6.9 | Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21997, CVE-2022-21999, CVE-2022-22718. |
CVE-2022-22001 | 09/02/22 | 7.2 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability. |
CVE-2022-22000 | 09/02/22 | 7.2 | Windows Common Log File System Driver Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21981. |
CVE-2022-21995 | 09/02/22 | 6.8 | Windows Hyper-V Remote Code Execution Vulnerability. |
CVE-2022-21993 | 09/02/22 | 7.8 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability. |
CVE-2022-21992 | 09/02/22 | 9.3 | Windows Mobile Device Management Remote Code Execution Vulnerability. |
CVE-2022-21989 | 09/02/22 | 6.9 | Windows Kernel Elevation of Privilege Vulnerability. |
CVE-2022-21974 | 09/02/22 | 9.3 | Roaming Security Rights Management Services Remote Code Execution Vulnerability. |
Windows Server 2019 Vulnerabilities
CVE Number | Date of Release | Severity | Description |
CVE-2022-22718 | 09/02/22 | 7.2 | Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21997, CVE-2022-21999, CVE-2022-22717. |
CVE-2022-22717 | 09/02/22 | 6.9 | Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21997, CVE-2022-21999, CVE-2022-22718. |
CVE-2022-22715 | 09/02/22 | 7.2 | Named Pipe File System Elevation of Privilege Vulnerability. |
CVE-2022-22001 | 09/02/22 | 7.2 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability. |
CVE-2022-22000 | 09/02/22 | 7.2 | Windows Common Log File System Driver Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21981. |
CVE-2022-21995 | 09/02/22 | 6.8 | Windows Hyper-V Remote Code Execution Vulnerability. |
CVE-2022-21994 | 09/02/22 | 7.2 | Windows DWM Core Library Elevation of Privilege Vulnerability. |
CVE-2022-21993 | 09/02/22 | 7.8 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability. |
CVE-2022-21992 | 09/02/22 | 9.3 | Windows Mobile Device Management Remote Code Execution Vulnerability. |
CVE-2022-21989 | 09/02/22 | 6.9 | Windows Kernel Elevation of Privilege Vulnerability. |
CVE-2022-21974 | 09/02/22 | 9.3 | Roaming Security Rights Management Services Remote Code Execution Vulnerability. |
CVE-2022-21971 | 09/02/22 | 9.3 | Windows Runtime Remote Code Execution Vulnerability. |
ESXi 6.7 Vulnerabilities
CVE Number | Date of Release | Severity | Description |
CVE-2021-22050 | 16/02/22 | 5 | ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service condition by overwhelming rhttpproxy service with multiple requests. |
CVE-2021-22043 | 16/02/22 | 6 | VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit this issue to escalate their privileges by writing arbitrary files. |
ESXi 7.0 Vulnerabilities
CVE Number | Date of Release | Severity | Description |
CVE-2021-22050 | 16/02/22 | 5 | ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service condition by overwhelming rhttpproxy service with multiple requests. |
CVE-2021-22045 | 04/01/22 | 6.9 | VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtual machine with CD-ROM device emulation may be able to exploit this vulnerability in conjunction with other issues to execute code on the hypervisor from a virtual machine. |
CVE-2021-22043 | 16/02/22 | 6 | VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit this issue to escalate their privileges by writing arbitrary files. |