Vulnerabilities > Linuxfoundation
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-10-07 | CVE-2022-32592 | Out-of-bounds Write vulnerability in multiple products In cpu dvfs, there is a possible out of bounds write due to a missing bounds check. | 6.7 |
2022-10-06 | CVE-2022-39222 | Missing Authorization vulnerability in Linuxfoundation DEX Dex is an identity service that uses OpenID Connect to drive authentication for other apps. | 6.5 |
2022-10-03 | CVE-2022-38817 | Missing Authentication for Critical Function vulnerability in Linuxfoundation Dapr Dashboard Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data. | 7.5 |
2022-09-24 | CVE-2022-36025 | Incorrect Conversion between Numeric Types vulnerability in Linuxfoundation Besu Besu is a Java-based Ethereum client. | 9.1 |
2022-09-09 | CVE-2022-31006 | Resource Exhaustion vulnerability in Linuxfoundation Indy-Node indy-node is the server portion of Hyperledger Indy, a distributed ledger purpose-built for decentralized identity. | 7.5 |
2022-09-06 | CVE-2022-31020 | Improper Input Validation vulnerability in Linuxfoundation Indy-Node Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. | 8.8 |
2022-08-12 | CVE-2022-35942 | SQL Injection vulnerability in Linuxfoundation Loopback-Connector-Postgresql Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection. | 10.0 |
2022-07-25 | CVE-2022-0670 | A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. | 9.1 |
2022-07-18 | CVE-2022-34632 | Use of a Broken or Risky Cryptographic Algorithm vulnerability in Linuxfoundation Rocket Chip Generator Rocket-Chip commit 4f8114374d8824dfdec03f576a8cd68bebce4e56 was discovered to contain insufficient cryptography via the component /rocket/RocketCore.scala. | 9.1 |
2022-07-12 | CVE-2022-31105 | Improper Certificate Validation vulnerability in multiple products Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. | 9.6 |