Linuxfoundation
linuxfoundation
552 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (552)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A reachable assertion in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cell...Show more |
3Google LinuxfoundationMediatek3Android Software Development KitYoctoJun 17, 2026 Jan 6, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not neede...Show more |
4Google LinuxfoundationMediatek+1 more4Android OpenwrtSoftware Development Kit+1 moreJun 17, 2026 Jan 6, 2025 N/A· v4 4.4 MEDIUM· v3 N/A· v2 In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction...Show more |
3Google LinuxfoundationMediatek3Android Software Development KitYoctoJun 17, 2026 Jan 6, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is n...Show more |
4Google LinuxfoundationMediatek+1 more4Android OpenwrtSoftware Development Kit+1 moreJun 17, 2026 Jan 6, 2025 N/A· v4 8.1 HIGH· v3 N/A· v2 In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction...Show more |
4Google LinuxfoundationOpenwrt+1 more4Android OpenwrtRdk B+1 moreJun 17, 2026 Jan 6, 2025 N/A· v4 6.6 MEDIUM· v3 N/A· v2 In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges...Show more |
4Google LinuxfoundationOpenwrt+1 more4Android OpenwrtRdk B+1 moreJun 17, 2026 Jan 6, 2025 N/A· v4 6.6 MEDIUM· v3 N/A· v2 In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges...Show more |
4Google LinuxfoundationOpenwrt+1 more4Android OpenwrtRdk B+1 moreJun 17, 2026 Jan 6, 2025 N/A· v4 6.6 MEDIUM· v3 N/A· v2 In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges...Show more |
2Google Linuxfoundation2Android YoctoJun 17, 2026 Jan 6, 2025 N/A· v4 6.7 MEDIUM· v3 N/A· v2 In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not ne...Show more |
4Google LinuxfoundationMediatek+1 more4Android OpenwrtSoftware Development Kit+1 moreJun 17, 2026 Dec 2, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of service with no additional execution privileges needed. User interaction...Show more |
Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts to read/update P2P preheat execution logs and specifying d...Show more |
Harbor fails to validate the user permissions when updating tag retention policies. By sending a request to update a tag retention policy with an id that belongs to a project that the currently authenticated user doesn...Show more |
Harbor fails to validate the user permissions when updating tag immutability policies. By sending a request to update a tag immutability policy with an id that belongs to a project that the currently authenticated user...Show more |
Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't hav...Show more |
Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access to. By sending a request that attempts to update a robot account, an...Show more |
Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users. The attacker could modify Webhook policies configured in ot...Show more |
4Google LinuxfoundationOpenwrt+1 more4Android OpenwrtRdk B+1 moreJun 17, 2026 Nov 4, 2024 N/A· v4 6.2 MEDIUM· v3 N/A· v2 In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation...Show more |
4Google LinuxfoundationOpenwrt+1 more4Android OpenwrtRdk B+1 moreJun 17, 2026 Nov 4, 2024 N/A· v4 8.4 HIGH· v3 N/A· v2 In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation....Show more |
In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing. |
1Linuxfoundation 1Zowe Api Mediation Layer Jun 17, 2026 Oct 10, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger....Show more |