Vulnerabilities > Linuxfoundation

DATE CVE VULNERABILITY TITLE RISK
2020-01-14 CVE-2020-6173 Resource Exhaustion vulnerability in Linuxfoundation the Update Framework
TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption.
network
low complexity
linuxfoundation CWE-400
5.3
2019-12-03 CVE-2019-3990 Improper Privilege Management vulnerability in Linuxfoundation Harbor
A User Enumeration flaw exists in Harbor.
network
low complexity
linuxfoundation CWE-269
4.3
2019-11-19 CVE-2011-2924 Link Following vulnerability in multiple products
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled.
5.5
2019-11-19 CVE-2011-2923 Link Following vulnerability in multiple products
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled.
local
low complexity
linuxfoundation debian CWE-59
5.5
2019-10-18 CVE-2019-16919 Incorrect Default Permissions vulnerability in multiple products
Harbor API has a Broken Access Control vulnerability.
network
low complexity
linuxfoundation vmware CWE-276
7.5
2019-09-25 CVE-2019-16884 Incorrect Authorization vulnerability in multiple products
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.
7.5
2019-09-08 CVE-2019-16097 Missing Authorization vulnerability in Linuxfoundation Harbor
core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration.
network
low complexity
linuxfoundation CWE-862
6.5
2019-07-22 CVE-2019-1010234 Improper Input Validation vulnerability in Linuxfoundation Open Network Operating System
The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation.
network
low complexity
linuxfoundation CWE-20
critical
9.8
2019-07-19 CVE-2019-1010245 OS Command Injection vulnerability in Linuxfoundation Open Network Operating System
The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation.
network
low complexity
linuxfoundation CWE-78
critical
9.8
2019-07-18 CVE-2019-1010252 Improper Input Validation vulnerability in Linuxfoundation Open Network Operating System
The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation.
network
low complexity
linuxfoundation CWE-20
4.9