Linuxfoundation
linuxfoundation
552 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (552)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectLinuxfoundation3Debian Linux FedoraFoomatic FiltersNov 21, 2024 Nov 19, 2019 N/A· v4 5.5 MEDIUM· v3 3.3 LOW· v2 foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduc...Show more |
2Debian Linuxfoundation2Debian Linux Foomatic FiltersNov 21, 2024 Nov 19, 2019 N/A· v4 5.5 MEDIUM· v3 3.3 LOW· v2 foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct s...Show more |
2Linuxfoundation Vmware3Cloud Foundation HarborHarbor Container RegistryJun 17, 2026 Oct 18, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project the...Show more |
6Canonical DockerFedoraproject+3 more10Docker Enterprise LinuxEnterprise Linux Eus+7 moreJun 17, 2026 Sep 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image...Show more |
core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. F...Show more |
2Linuxfoundation Nats2Nats Server Nats ServerJun 17, 2026 Jul 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An integer overflow in NATS Server before 2.0.2 allows a remote attacker to crash the server by sending a crafted request. If authentication is enabled, then the remote attacker must have first authenticated. |
1Linuxfoundation 1Open Network Operating System Jun 17, 2026 Jul 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation. The impact is: The attacker can remotely execute any commands by sending malicious http request to the controller. The component is:...Show more |
1Linuxfoundation 1Open Network Operating System Jun 17, 2026 Jul 19, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact is: A remote attacker can execute arbitrary commands on the controller. The component is: apps/yang...Show more |
1Linuxfoundation 1Open Network Operating System Jun 17, 2026 Jul 18, 2019 N/A· v4 4.9 MEDIUM· v3 5.5 MEDIUM· v2 The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: applyF...Show more |
1Linuxfoundation 1Open Network Operating System Jun 17, 2026 Jul 18, 2019 N/A· v4 4.9 MEDIUM· v3 5.5 MEDIUM· v2 The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: create...Show more |
1Linuxfoundation 1Open Network Operating System Jun 17, 2026 Jul 18, 2019 N/A· v4 4.9 MEDIUM· v3 5.5 MEDIUM· v2 The Linux Foundation ONOS 2.0.0 and earlier is affected by: Integer Overflow. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: createFlow(...Show more |
In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder of a malicious binary to a folder with known 'safe' permissions. Under those cir...Show more |
13Apache CanonicalD2iq+10 more19Backports Sle Container Development KitDc/os+16 moreJun 17, 2026 Feb 11, 2019 N/A· v4 8.6 HIGH· v3 9.3 HIGH· v2 runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as r...Show more |
An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool wi...Show more |
1Linuxfoundation 1Opendaylight Nov 21, 2024 Apr 27, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The odl-mdsal-apidocs feature in OpenDaylight Helium allow remote attackers to obtain sensitive information by leveraging missing AAA restrictions. |
The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping. |
3Docker LinuxfoundationOpensuse3Docker OpensuseRuncMay 6, 2026 Jun 1, 2016 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password...Show more |
3Linuxfoundation OracleRedhat8Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+5 moreMay 6, 2026 Apr 15, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code...Show more |
3Canonical DebianLinuxfoundation4Cups Filters Debian LinuxFoomatic Filters+1 moreMay 6, 2026 Apr 14, 2016 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) charact...Show more |
4Canonical DebianLinuxfoundation+1 more9Cups Filters Debian LinuxEnterprise Linux Desktop+6 moreMay 6, 2026 Dec 17, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters...Show more |