Vulnerability index

Browse CVEs

414 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Harbor HIGH 8.8
CVE-2019-19023

Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware Harbor Container Registry fo…

Fix: 1.8.6 / 1.9.3+
Fix from $1,950 2020-03-20
Harbor HIGH 8.8
CVE-2019-19025

Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry for the Pivotal Platform.

Fix: 1.8.6 / 1.9.3+
Fix from $1,950 2020-03-20
Harbor HIGH 7.2
CVE-2019-19029

Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Harbor Container Registry for th…

Fix: 1.8.6 / 1.9.3+
Fix from $1,950 2020-03-20
Osquery CRITICAL 9.1
CVE-2020-1887

Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker to MITM osquery traffic in the …

Fix: 4.2.0+
Fix from $2,300 2020-03-13
Dojox HIGH 8.6
CVE-2020-5259

In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inje…

Fix: 1.11.10 / 1.12.8+
Fix from $1,950 2020-03-10
Open Network Operating System HIGH 7.5
CVE-2019-16297

An issue was discovered in Open Network Operating System (ONOS) 1.14. In the P4 tutorial application (org.onosproject.p4tutorial), the host event lis…

Mitigation only
Fix from $1,950 2020-02-20
Open Network Operating System HIGH 7.5
CVE-2019-16298

An issue was discovered in Open Network Operating System (ONOS) 1.14. In the virtual broadband network gateway application (org.onosproject.virtualbn…

Mitigation only
Fix from $1,950 2020-02-20
Open Network Operating System HIGH 7.5
CVE-2019-16299

An issue was discovered in Open Network Operating System (ONOS) 1.14. In the mobility application (org.onosproject.mobility), the host event listener…

Mitigation only
Fix from $1,950 2020-02-20
Open Network Operating System HIGH 7.5
CVE-2019-16300

An issue was discovered in Open Network Operating System (ONOS) 1.14. In the access control application (org.onosproject.acl), the host event listene…

Mitigation only
Fix from $1,950 2020-02-20
Open Network Operating System HIGH 7.5
CVE-2019-16301

An issue was discovered in Open Network Operating System (ONOS) 1.14. In the virtual tenant network application (org.onosproject.vtn), the host event…

Mitigation only
Fix from $1,950 2020-02-20
Open Network Operating System HIGH 7.5
CVE-2019-16302

An issue was discovered in Open Network Operating System (ONOS) 1.14. In the Ethernet VPN application (org.onosproject.evpnopenflow), the host event …

Mitigation only
Fix from $1,950 2020-02-20
The Update Framework CRITICAL 9.8
CVE-2020-6174

TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.

Fix: after 0.12.1
Fix from $2,300 2020-02-05
The Update Framework MEDIUM 5.3
CVE-2020-6173

TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption.

Fix: after 0.12.1
Fix from $1,600 2020-01-14
Harbor MEDIUM 6.5
CVE-2019-16097EPSS 22%

core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with…

Patch available
Fix from $1,600 2019-09-08
Nats Server HIGH 7.5
CVE-2019-13126

An integer overflow in NATS Server before 2.0.2 allows a remote attacker to crash the server by sending a crafted request. If authentication is enabl…

Fix: 2.0.2+
Fix from $1,950 2019-07-29
Open Network Operating System CRITICAL 9.8
CVE-2019-1010234

The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation. The impact is: The attacker can remotely execute any commands …

Fix: after 1.15.0
Fix from $2,300 2019-07-22
Open Network Operating System CRITICAL 9.8
CVE-2019-1010245

The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact is: A remote attacker can ex…

Fix: after 1.15
Fix from $2,300 2019-07-19
Osquery HIGH 8.1
CVE-2019-3567

In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder of a mali…

Fix: 3.4.0+
Fix from $1,950 2019-06-03
Osquery HIGH 7.8
CVE-2018-6336

An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full insp…

Fix: 3.2.7+
Fix from $1,950 2018-12-31
Opendaylight MEDIUM 5.3
CVE-2015-1857

The odl-mdsal-apidocs feature in OpenDaylight Helium allow remote attackers to obtain sensitive information by leveraging missing AAA restrictions.

Fix: 0.2.4+
Fix from $1,600 2018-04-27
Harbor HIGH 8.6
CVE-2017-17697

The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.

Fix: 1.3.0+
Fix from $1,950 2017-12-15
Cups Filters MEDIUM 5.8
CVE-2014-4336

The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitra…

Fix: after 1.0.52
Fix from $1,600 2014-06-22
Cups Filters HIGH 8.3
CVE-2014-2707

cups-browsed in cups-filters 1.0.41 before 1.0.51 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the (1) model …

Mitigation only
Fix from $1,950 2014-04-17
Foomatic MEDIUM 6.8
CVE-2011-2964

foomaticrip.c in foomatic-rip in foomatic-filters in Foomatic 4.0.6 allows remote attackers to execute arbitrary code via a crafted *FoomaticRIPComma…

Patch available
Fix from $1,600 2011-07-29