Vulnerabilities > Linuxfoundation > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-02-20 CVE-2019-16299 Improper Handling of Exceptional Conditions vulnerability in Linuxfoundation Open Network Operating System 1.14.0
An issue was discovered in Open Network Operating System (ONOS) 1.14.
network
low complexity
linuxfoundation CWE-755
5.0
2020-02-20 CVE-2019-16298 Improper Handling of Exceptional Conditions vulnerability in Linuxfoundation Open Network Operating System 1.14.0
An issue was discovered in Open Network Operating System (ONOS) 1.14.
network
low complexity
linuxfoundation CWE-755
5.0
2020-02-20 CVE-2019-16297 Improper Handling of Exceptional Conditions vulnerability in Linuxfoundation Open Network Operating System 1.14.0
An issue was discovered in Open Network Operating System (ONOS) 1.14.
network
low complexity
linuxfoundation CWE-755
5.0
2020-02-13 CVE-2019-10785 Cross-site Scripting vulnerability in multiple products
dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9.
network
low complexity
linuxfoundation debian CWE-79
6.1
2020-01-14 CVE-2020-6173 Resource Exhaustion vulnerability in Linuxfoundation the Update Framework
TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption.
network
low complexity
linuxfoundation CWE-400
5.0
2019-12-03 CVE-2019-3990 Improper Privilege Management vulnerability in Linuxfoundation Harbor
A User Enumeration flaw exists in Harbor.
network
low complexity
linuxfoundation CWE-269
4.0
2019-10-18 CVE-2019-16919 Incorrect Default Permissions vulnerability in multiple products
Harbor API has a Broken Access Control vulnerability.
network
low complexity
linuxfoundation vmware CWE-276
5.0
2019-09-08 CVE-2019-16097 Missing Authorization vulnerability in Linuxfoundation Harbor
core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration.
network
low complexity
linuxfoundation CWE-862
4.0
2019-07-18 CVE-2019-1010252 Improper Input Validation vulnerability in Linuxfoundation Open Network Operating System
The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation.
network
low complexity
linuxfoundation CWE-20
5.5
2019-07-18 CVE-2019-1010250 Improper Input Validation vulnerability in Linuxfoundation Open Network Operating System
The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation.
network
low complexity
linuxfoundation CWE-20
5.5