Vulnerabilities > Linuxfoundation

DATE CVE VULNERABILITY TITLE RISK
2022-11-16 CVE-2022-39383 Server-Side Request Forgery (SSRF) vulnerability in Linuxfoundation Kubevela
KubeVela is an open source application delivery platform.
network
low complexity
linuxfoundation CWE-918
6.5
2022-11-14 CVE-2022-0324 Classic Buffer Overflow vulnerability in Linuxfoundation Software for Open Networking in the Cloud 202111
There is a vulnerability in DHCPv6 packet parsing code that could be explored by remote attacker to craft a packet that could cause buffer overflow in a memcpy call, leading to out-of-bounds memory write that would cause dhcp6relay to crash.
network
low complexity
linuxfoundation CWE-120
7.5
2022-10-07 CVE-2022-26475 Out-of-bounds Write vulnerability in multiple products
In wlan, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
linuxfoundation google CWE-787
6.7
2022-10-07 CVE-2022-32589 Improper Resource Shutdown or Release vulnerability in multiple products
In Wi-Fi driver, there is a possible way to disconnect Wi-Fi due to an improper resource release.
network
low complexity
google linuxfoundation CWE-404
7.5
2022-10-07 CVE-2022-32590 Improper Check for Unusual or Exceptional Conditions vulnerability in multiple products
In wlan, there is a possible use after free due to an incorrect status check.
local
low complexity
linuxfoundation google CWE-754
6.7
2022-10-07 CVE-2022-32592 Out-of-bounds Write vulnerability in multiple products
In cpu dvfs, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
google linuxfoundation CWE-787
6.7
2022-10-06 CVE-2022-39222 Missing Authorization vulnerability in Linuxfoundation DEX
Dex is an identity service that uses OpenID Connect to drive authentication for other apps.
network
low complexity
linuxfoundation CWE-862
6.5
2022-10-03 CVE-2022-38817 Missing Authentication for Critical Function vulnerability in Linuxfoundation Dapr Dashboard
Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data.
network
low complexity
linuxfoundation CWE-306
7.5
2022-09-24 CVE-2022-36025 Incorrect Conversion between Numeric Types vulnerability in Linuxfoundation Besu
Besu is a Java-based Ethereum client.
network
low complexity
linuxfoundation CWE-681
critical
9.1
2022-07-25 CVE-2022-0670 A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system.
network
low complexity
linuxfoundation redhat fedoraproject
critical
9.1