Vulnerabilities > Linuxfoundation

DATE CVE VULNERABILITY TITLE RISK
2024-08-02 CVE-2024-22278 Unspecified vulnerability in Linuxfoundation Harbor
Incorrect user permission validation in Harbor <v2.9.5 and Harbor <v2.10.3 allows authenticated users to modify configurations.
network
low complexity
linuxfoundation
4.3
2024-07-01 CVE-2024-20081 Out-of-bounds Write vulnerability in multiple products
In gnss service, there is a possible out of bounds write due to improper input validation.
6.7
2024-06-06 CVE-2024-5187 Unspecified vulnerability in Linuxfoundation Onnx 1.16.0
A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files.
network
low complexity
linuxfoundation
8.8
2024-03-04 CVE-2024-20022 In lk, there is a possible escalation of privilege due to a missing bounds check.
local
low complexity
linuxfoundation rdkcentral google openwrt
6.7
2024-02-23 CVE-2024-27318 Path Traversal vulnerability in multiple products
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory.
network
low complexity
linuxfoundation fedoraproject CWE-22
7.5
2024-02-23 CVE-2024-27319 Out-of-bounds Read vulnerability in multiple products
Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.
network
low complexity
linuxfoundation fedoraproject CWE-125
critical
9.1
2024-02-23 CVE-2024-26150 Path Traversal vulnerability in Linuxfoundation Backstage Backend-Common 0.21.0
`@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building developer portals.
network
low complexity
linuxfoundation CWE-22
7.5
2024-02-19 CVE-2024-25626 OS Command Injection vulnerability in Linuxfoundation Yocto
Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless of the hardware architecture.
network
low complexity
linuxfoundation CWE-78
critical
9.8
2024-01-31 CVE-2024-21626 Exposure of Resource to Wrong Sphere vulnerability in multiple products
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification.
local
low complexity
linuxfoundation fedoraproject CWE-668
8.6
2024-01-25 CVE-2024-23656 Inadequate Encryption Strength vulnerability in Linuxfoundation DEX 2.37.0
Dex is an identity service that uses OpenID Connect to drive authentication for other apps.
network
low complexity
linuxfoundation CWE-326
7.5