Vulnerability index

Browse CVEs

414 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Yocto CRITICAL 9.8
CVE-2024-25626

Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless of the hardware architecture…

Fix: 3.1.31 / 4.0.16+
Fix from $2,300 2024-02-19
Dex HIGH 7.5
CVE-2024-23656

Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS 1.1…

Patch available
Fix from $1,950 2024-01-25
Cubefs MEDIUM 6.5
CVE-2023-46742

CubeFS is an open-source cloud-native file storage system. CubeFS prior to version 3.3.1 was found to leak users secret keys and access keys in the l…

Fix: 3.3.1+
Fix from $1,600 2024-01-03
Cubefs CRITICAL 9.8
CVE-2023-46740

CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string generator to generate user-s…

Fix: 3.3.1+
Fix from $2,300 2024-01-03
Cubefs CRITICAL 9.8
CVE-2023-46741

CubeFS is an open-source cloud-native file storage system. A vulnerability was found in CubeFS prior to version 3.3.1 that could allow users to read …

Fix: 3.3.1+
Fix from $2,300 2024-01-03
Cubefs MEDIUM 5.9
CVE-2023-46739

CubeFS is an open-source cloud-native file storage system. A vulnerability was found during in the CubeFS master component in versions prior to 3.3.1…

Fix: 3.3.1+
Fix from $1,600 2024-01-03
Cubefs MEDIUM 6.5
CVE-2023-46738

CubeFS is an open-source cloud-native file storage system. A security vulnerability was found in CubeFS HandlerNode in versions prior to 3.3.1 that c…

Fix: 3.3.1+
Fix from $1,600 2024-01-03
Yocto MEDIUM 6.7
CVE-2023-32855

In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System e…

Mitigation only
Fix from $1,600 2023-12-04
Harbor MEDIUM 6.5
CVE-2023-20902

A timing condition in Harbor 2.6.x and below, Harbor 2.7.2 and below,  Harbor 2.8.2 and below, and Harbor 1.10.17 and below allows an attacker with n…

Fix: 1.10.17 / 2.7.3+
Fix from $1,600 2023-11-09
Nats Server HIGH 7.5
CVE-2023-46129

NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The…

Fix: 0.4.6 / 2.10.4+
Fix from $1,950 2023-10-31
Nats Server MEDIUM 6.5
CVE-2023-47090

NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be …

Fix: 2.9.23 / 2.10.2+
Fix from $1,600 2023-10-30
Yocto MEDIUM 6.7
CVE-2023-32829

In apusys, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution…

Mitigation only
Fix from $1,600 2023-10-02
Edge Virtualization Engine CRITICAL 9.9
CVE-2023-43632

As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port 8877 in EVE, exposing limited functionality of the TPM t…

Fix: 9.5.0+
Fix from $2,300 2023-09-21
Edge Virtualization Engine HIGH 8.8
CVE-2023-43631

On boot, the Pillar eve container checks for the existence and content of “/config/authorized_keys”. If the file is present, and contains a supporte…

Fix: 8.6.0 / 9.5.0+
Fix from $1,950 2023-09-21
Edge Virtualization Engine HIGH 8.8
CVE-2023-43636

In EVE OS, the “measured boot” mechanism prevents a compromised device from accessing the encrypted data located in the vault. As per the “measured …

Fix: 8.6.0 / 9.5.0+
Fix from $1,950 2023-09-20
Edge Virtualization Engine HIGH 8.8
CVE-2023-43630

PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but due to the change that was implemented in commit “7638364bc0acf8b5c481b5ce5fea…

Fix: 9.5.0+
Fix from $1,950 2023-09-20
Edge Virtualization Engine HIGH 8.8
CVE-2023-43635

Vault Key Sealed With SHA1 PCRs The measured boot solution implemented in EVE OS leans on a PCR locking mechanism. Different parts of the syst…

Fix: 9.5.0+
Fix from $1,950 2023-09-20
Nats Server CRITICAL 9.8
CVE-2022-28357

NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.

Fix: after 2.7.4
Fix from $2,300 2023-09-19
Yocto MEDIUM 6.7
CVE-2023-32811

In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privi…

Mitigation only
Fix from $1,600 2023-09-04
Yocto MEDIUM 6.7
CVE-2023-32812

In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local esclation of privileges with Syst…

Mitigation only
Fix from $1,600 2023-09-04
Yocto MEDIUM 6.7
CVE-2023-32806

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with Syste…

Mitigation only
Fix from $1,600 2023-09-04
Yocto MEDIUM 6.4
CVE-2023-20835

In camsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privile…

Mitigation only
Fix from $1,600 2023-09-04
Yocto MEDIUM 6.7
CVE-2023-20828

In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…

Mitigation only
Fix from $1,600 2023-09-04
Yocto MEDIUM 6.7
CVE-2023-20829

In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…

Mitigation only
Fix from $1,600 2023-09-04
Yocto MEDIUM 6.7
CVE-2023-20830

In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…

Mitigation only
Fix from $1,600 2023-09-04
Yocto MEDIUM 6.7
CVE-2023-20831

In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…

Mitigation only
Fix from $1,600 2023-09-04
Yocto MEDIUM 6.7
CVE-2023-20832

In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…

Mitigation only
Fix from $1,600 2023-09-04
Yocto MEDIUM 6.7
CVE-2023-20821

In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executi…

Mitigation only
Fix from $1,600 2023-09-04
Spinnaker MEDIUM 5.3
CVE-2023-39348

Spinnaker is an open source, multi-cloud continuous delivery platform. Log output when updating GitHub status is improperly set to FULL always. It's…

Fix: 1.28.8 / 1.29.6+
Fix from $1,600 2023-08-28
Opentelemetry Instrumentation For Java MEDIUM 6.5
CVE-2023-39951

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. OpenTelemetry Java Instrumenta…

Fix: 1.28.0+
Fix from $1,600 2023-08-08