Vulnerabilities > Clusterlabs > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-08-08 CVE-2023-39976 Classic Buffer Overflow vulnerability in Clusterlabs Libqb
log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not considered.
network
low complexity
clusterlabs CWE-120
critical
9.8
2023-05-17 CVE-2023-2319 It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via erratum RHSA-2023:1591.
network
low complexity
clusterlabs redhat
critical
9.8
2021-01-12 CVE-2020-35458 Code Injection vulnerability in Clusterlabs Hawk 2.2.012/2.3.012
An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x.
network
low complexity
clusterlabs CWE-94
critical
10.0