LiveActive security incident?Get immediate response
CVE archive

November 2022

Browse CVE records published in November 2022, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2075 matching CVEs · Page 8 of 42.

Medium · CVSS 5.4

CVE-2022-31777: Apache Spark XSS vulnerability in log viewer UI Javascript

A stored cross-site scripting (XSS) vulnerability in Apache Spark 3.2.1 and earlier, and 3.3.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the logs which would be returned in logs rendered in the UI.

Published Nov 1, 2022 · Updated May 6, 2025

Medium · CVSS 6.5

CVE-2022-32923: A correctness issue in the JIT was addressed with improved checks.

A correctness issue in the JIT was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose internal states of the app.

Published Nov 1, 2022 · Updated May 6, 2025

High · CVSS 7.8

CVE-2022-32924: The issue was addressed with improved memory handling.

The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Big Sur 11.7, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6. An app may be able to execute arbitrary code with kernel privileges.

Published Nov 1, 2022 · Updated May 6, 2025

Low · CVSS 3

CVE-2022-43562: Host Header Injection in Splunk Enterprise

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape the Host header, which could let a remote authenticated user conduct various attacks against the system, including cross-site scripting and cache poisoning.

Published Nov 4, 2022 · Updated May 5, 2025

High · CVSS 8.1

CVE-2022-43563: Risky command safeguards bypass via rex search command field names in Splunk Enterprise

In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names lets an attacker bypass SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards . The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The attacker cannot exploit the vulnerability at will.

Published Nov 4, 2022 · Updated May 5, 2025

High · CVSS 8.1

CVE-2022-43565: Risky command safeguards bypass via ‘tstats command JSON in Splunk Enterprise

In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javascript Object Notation (JSON) lets an attacker bypass SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards . The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser.

Published Nov 4, 2022 · Updated May 5, 2025

High · CVSS 7.3

CVE-2022-43566: Risky command safeguards bypass via Search ID query in Analytics Workspace in Splunk Enterprise

In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run risky commands using a more privileged user’s permissions to bypass SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards  in the Analytics Workspace. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The attacker cannot exploit the vulnerability at will.

Published Nov 4, 2022 · Updated May 5, 2025

Medium · CVSS 4.3

CVE-2022-2387: Easy Digital Downloads < 3.0 - Arbitrary Post Deletion via CSRF

The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history, and does not ensure that the post to be deleted is actually a payment history. As a result, attackers could make a logged in admin delete arbitrary post via a CSRF attack

Published Nov 7, 2022 · Updated May 5, 2025

High · CVSS 7.2

CVE-2022-2711: WP All Import < 3.6.9 - Admin+ Directory traversal via file upload

The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as admins, to write arbitrary files to any part of the file system accessible by the web server via a path traversal vector.

Published Nov 7, 2022 · Updated May 5, 2025

High · CVSS 8.6

CVE-2022-3872: An off-by-one read/write issue was found in the SDHCI device of QEMU.

An off-by-one read/write issue was found in the SDHCI device of QEMU. It occurs when reading/writing the Buffer Data Port Register in sdhci_read_dataport and sdhci_write_dataport, respectively, if data_count == block_size. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.

Published Nov 7, 2022 · Updated May 5, 2025

Medium · CVSS 6.5

CVE-2022-42316: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs;...

Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large memory allocations in xenstored: - - by issuing new requests to xenstored without reading the responses, causing the responses to be buffered in memory - - by causing large number of watch events to be generated via setting up multiple xenstore watches and then e.g. deleting many xenstore nodes below the watched path - - by creating as many nodes as allowed with the maximum allowed size and path length in as many transactions as possible - - by accessing many nodes inside a transaction

Published Nov 1, 2022 · Updated May 5, 2025

Medium · CVSS 6.5

CVE-2022-42317: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs;...

Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large memory allocations in xenstored: - - by issuing new requests to xenstored without reading the responses, causing the responses to be buffered in memory - - by causing large number of watch events to be generated via setting up multiple xenstore watches and then e.g. deleting many xenstore nodes below the watched path - - by creating as many nodes as allowed with the maximum allowed size and path length in as many transactions as possible - - by accessing many nodes inside a transaction

Published Nov 1, 2022 · Updated May 5, 2025

Medium · CVSS 5.5

CVE-2022-42788: A permissions issue existed.

A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in macOS Ventura 13. A malicious application may be able to read sensitive location information.

Published Nov 1, 2022 · Updated May 5, 2025

Medium · CVSS 6.5

CVE-2022-42318: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs;...

Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how guests can cause large memory allocations in xenstored: - - by issuing new requests to xenstored without reading the responses, causing the responses to be buffered in memory - - by causing large number of watch events to be generated via setting up multiple xenstore watches and then e.g. deleting many xenstore nodes below the watched path - - by creating as many nodes as allowed with the maximum allowed size and path length in as many transactions as possible - - by accessing many nodes inside a transaction

Published Nov 1, 2022 · Updated May 5, 2025

Medium · CVSS 5.5

CVE-2022-42798: The issue was addressed with improved memory handling.

The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. Parsing a maliciously crafted audio file may lead to disclosure of user information.

Published Nov 1, 2022 · Updated May 5, 2025

Medium · CVSS 6.1

CVE-2022-42799: The issue was addressed with improved UI handling.

The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Visiting a malicious website may lead to user interface spoofing.

Published Nov 1, 2022 · Updated May 5, 2025