CVEs (326)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject Gpgme ProjectRedhat9Enterprise Linux For Ibm Z Systems Enterprise Linux For Power Little EndianEnterprise Linux Server+6 moreJun 17, 2026 Feb 12, 2020 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signatu...Show more |
5Canonical DebianLinuxfoundation+2 more5Debian Linux LeapOpenshift Container Platform+2 moreJun 17, 2026 Feb 12, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount...Show more |
2Libpod Project Redhat3Enterprise Linux LibpodOpenshift Container PlatformJun 17, 2026 Feb 11, 2020 N/A· v4 5.9 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container bas...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Feb 7, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers modify the permissions of /etc/passwd to make them modifiable by users oth...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Jan 7, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw ca...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Jan 7, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret mater...Show more |
8Canonical DebianFedoraproject+5 more15Backports Sle ChromeCommunications Cloud Native Core Network Repository Function+12 moreJun 17, 2026 Dec 10, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Kubernetes Redhat4External Provisioner External ResizerExternal Snapshotter+1 moreJun 17, 2026 Dec 5, 2019 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2)...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Nov 25, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discove...Show more |
3Fedoraproject KubernetesRedhat3Cri O FedoraOpenshift Container PlatformJun 17, 2026 Nov 25, 2019 N/A· v4 5.0 MEDIUM· v3 6.0 MEDIUM· v2 A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of...Show more |
5Buildah Project Libpod ProjectOpensuse+2 more6Buildah Enterprise LinuxLeap+3 moreJun 17, 2026 Nov 25, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container regi...Show more |
8Canonical DebianF5+5 more778Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+775 moreNov 21, 2024 Nov 14, 2019 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local acces...Show more |
2Kubernetes Redhat2Kube State Metrics Openshift Container PlatformJun 17, 2026 Nov 5, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-...Show more |
7Canonical DebianFedoraproject+4 more15Debian Linux Element Software Management NodeEnterprise Linux+12 moreJun 17, 2026 Oct 17, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For exa...Show more |
2Kubernetes Redhat2Kubernetes Openshift Container PlatformJun 17, 2026 Oct 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API...Show more |
6Debian FedoraprojectGolang+3 more9Cloud Insights Telegraf Agent Debian LinuxDeveloper Tools+6 moreJun 17, 2026 Sep 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling. |
6Canonical DockerFedoraproject+3 more10Docker Enterprise LinuxEnterprise Linux Eus+7 moreJun 17, 2026 Sep 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image...Show more |
8Canonical DebianFedoraproject+5 more34Aff A700s Firmware Data Availability ServicesDebian Linux+31 moreJun 17, 2026 Sep 17, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged gu...Show more |
5Artifex DebianFedoraproject+2 more12Debian Linux Enterprise LinuxEnterprise Linux Desktop+9 moreJun 17, 2026 Sep 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted Po...Show more |
3Fedoraproject RedhatSystemd Project14Enterprise Linux Enterprise Linux EusEnterprise Linux For Ibm Z Systems 8 S390x+11 moreJun 17, 2026 Sep 4, 2019 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incomin...Show more |