Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.6
CVE-2022-23538
github.com/sylabs/scs-library-client is the Go client for the Singularity Container Services (SCS) Container Library Service. When the scs-library-cl…
Singularity Container Services Library
Patch available
CRITICAL 9.8
CVE-2022-39237
syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` pa…
Singularity Image Format
2.8.1+
CRITICAL 9.8
CVE-2021-33027
Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.
Singularity
1.2.6 / 1.3.4+
CRITICAL 9.8
CVE-2021-33622
Sylabs Singularity 3.5.x and 3.6.x, and SingularityPRO before 3.5-8, has an Incorrect Check of a Function's Return Value.
Singularity
3.5-8 / 3.7.0+
MEDIUM 6.3
CVE-2021-32635
Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`…
Singularity
Mitigation only
HIGH 7.5
CVE-2021-29499
SIF is an open source implementation of the Singularity Container Image Format. The `siftool new` command and func siftool.New() produce predictable …
Singularity Image Format
1.2.3+
CRITICAL 9.3
CVE-2020-15229
Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of path traversal and …
Singularity
after 3.6.3
HIGH 8.8
CVE-2020-25040
Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a differ…
Singularity
after 3.6.2
HIGH 8.1
CVE-2020-25039
Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution.
Singularity
after 3.6.2
HIGH 7.5
CVE-2020-13845
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforc…
Singularity
after 3.5.0
HIGH 7.5
CVE-2020-13846
Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.
Singularity
after 3.5.3
HIGH 7.5
CVE-2020-13847
Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the glo…
Singularity
after 3.5.0
HIGH 7.5
CVE-2019-19724
Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to a…
Singularity
after 3.5.1
HIGH 7.8
CVE-2018-19295
Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks.
Singularity
after 2.6.0
MEDIUM 6.5
CVE-2018-12021
Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, …
Singularity
after 2.5.1