Vulnerabilities > Linuxfoundation

DATE CVE VULNERABILITY TITLE RISK
2022-10-07 CVE-2022-32592 Out-of-bounds Write vulnerability in multiple products
In cpu dvfs, there is a possible out of bounds write due to a missing bounds check.
local
low complexity
linuxfoundation google CWE-787
6.7
2022-10-06 CVE-2022-39222 Missing Authorization vulnerability in Linuxfoundation DEX
Dex is an identity service that uses OpenID Connect to drive authentication for other apps.
network
low complexity
linuxfoundation CWE-862
6.5
2022-10-03 CVE-2022-38817 Missing Authentication for Critical Function vulnerability in Linuxfoundation Dapr Dashboard
Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data.
network
low complexity
linuxfoundation CWE-306
7.5
2022-09-24 CVE-2022-36025 Incorrect Conversion between Numeric Types vulnerability in Linuxfoundation Besu
Besu is a Java-based Ethereum client.
network
low complexity
linuxfoundation CWE-681
critical
9.1
2022-09-09 CVE-2022-31006 Resource Exhaustion vulnerability in Linuxfoundation Indy-Node
indy-node is the server portion of Hyperledger Indy, a distributed ledger purpose-built for decentralized identity.
network
low complexity
linuxfoundation CWE-400
7.5
2022-09-06 CVE-2022-31020 Improper Input Validation vulnerability in Linuxfoundation Indy-Node
Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity.
network
low complexity
linuxfoundation CWE-20
8.8
2022-08-12 CVE-2022-35942 SQL Injection vulnerability in Linuxfoundation Loopback-Connector-Postgresql
Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection.
network
low complexity
linuxfoundation CWE-89
critical
10.0
2022-07-25 CVE-2022-0670 A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system.
network
low complexity
linuxfoundation redhat fedoraproject
critical
9.1
2022-07-18 CVE-2022-34632 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Linuxfoundation Rocket Chip Generator
Rocket-Chip commit 4f8114374d8824dfdec03f576a8cd68bebce4e56 was discovered to contain insufficient cryptography via the component /rocket/RocketCore.scala.
network
low complexity
linuxfoundation CWE-327
critical
9.1
2022-07-12 CVE-2022-31105 Improper Certificate Validation vulnerability in multiple products
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.
network
low complexity
linuxfoundation argoproj CWE-295
critical
9.6