Msrc Azl3 Python-Tensorboard 2.11.0-3 On Azure Linux 3.0 vulnerabilities

30 known vulnerabilities affecting msrc/azl3_python-tensorboard_2.11.0-3_on_azure_linux_3.0.

Total CVEs
30
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH20MEDIUM7

Vulnerabilities

Page 1 of 2
CVE-2023-26159HIGHCVSS 7.32024-01-09
CVE-2023-26159 [HIGH] CWE-601 Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error it c Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error it can be manipulated to misinterpret the hostname. An attacker could exp
msrc
CVE-2022-46175HIGHCVSS 7.12022-12-13
CVE-2022-46175 [HIGH] CWE-1321 JSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The `parse` method of the JSON5 library before and including version JSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The `parse` method of the JSON5 library before and including versions 1.0.1 and 2.2.1 does not restrict parsing of keys named `__proto__
msrc
CVE-2022-39353CRITICALCVSS 9.82022-11-08
CVE-2022-39353 [CRITICAL] CWE-20 xmldom allows multiple root nodes in a DOM xmldom allows multiple root nodes in a DOM FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed.
msrc
CVE-2022-3509HIGHCVSS 7.52022-11-08
CVE-2022-3509 [HIGH] Parsing issue in protobuf textformat Parsing issue in protobuf textformat FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed t
msrc
CVE-2022-37616CRITICALCVSS 9.82022-10-11
CVE-2022-37616 [CRITICAL] CWE-1321 A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we a A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however so
msrc
CVE-2022-3171HIGHCVSS 7.52022-10-11
CVE-2022-3171 [MEDIUM] CWE-20 Memory handling vulnerability in ProtocolBuffers Java core and lite Memory handling vulnerability in ProtocolBuffers Java core and lite FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open sourc
msrc
CVE-2022-24921HIGHCVSS 7.52022-03-08
CVE-2022-24921 [HIGH] CWE-674 regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression. regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is th
msrc
CVE-2022-23806CRITICALCVSS 9.12022-02-08
CVE-2022-23806 [CRITICAL] CWE-252 Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element. Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore pote
msrc
CVE-2022-23772HIGHCVSS 7.52022-02-08
CVE-2022-23772 [HIGH] CWE-190 Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption. Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who
msrc
CVE-2021-22569MEDIUMCVSS 5.52022-01-11
CVE-2021-22569 [HIGH] CWE-696 Denial of Service of protobuf-java parsing procedure Denial of Service of protobuf-java parsing procedure FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the dis
msrc
CVE-2021-41771HIGHCVSS 7.52021-11-09
CVE-2021-41771 [HIGH] CWE-119 ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer aka an out-of-bounds slice situation. ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer aka an out-of-bounds slice situation. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and
msrc
CVE-2021-41772HIGHCVSS 7.52021-11-09
CVE-2021-41772 [HIGH] CWE-20 Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field. Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerabil
msrc
CVE-2021-33195HIGHCVSS 7.32021-08-10
CVE-2021-33195 [HIGH] CWE-74 Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers and thus a return value may contain an unsafe injection (e.g. XSS) that does not Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers and thus a return value may contain an unsafe injection (e.g. XSS) that does not conform to the RFC1035 format. FAQ: Is Azure Linux the only Microsoft
msrc
CVE-2021-33198HIGHCVSS 7.52021-08-10
CVE-2021-33198 [HIGH] In Go before 1.15.13 and 1.16.x before 1.16.5 there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method. In Go before 1.15.13 and 1.16.x before 1.16.5 there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers wh
msrc
CVE-2021-33196HIGHCVSS 7.52021-08-10
CVE-2021-33196 [HIGH] CWE-20 In archive/zip in Go before 1.15.13 and 1.16.x before 1.16.5 a crafted file count (in an archive's header) can cause a NewReader or OpenReader panic. In archive/zip in Go before 1.15.13 and 1.16.x before 1.16.5 a crafted file count (in an archive's header) can cause a NewReader or OpenReader panic. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefit
msrc
CVE-2021-29923HIGHCVSS 7.52021-08-10
CVE-2021-29923 [HIGH] Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet which (in some situations) allows attackers to bypass access control that is based on IP ad Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet which (in some situations) allows attackers to bypass access control that is based on IP addresses because of unexpected octal interpretation. This affects net.ParseIP
msrc
CVE-2021-33197MEDIUMCVSS 5.32021-08-10
CVE-2021-33197 [MEDIUM] CWE-862 In Go before 1.15.13 and 1.16.x before 1.16.5 some configurations of ReverseProxy (from net/http/httputil) result in a situation where an attacker is able to drop arbitrary headers. In Go before 1.15.13 and 1.16.x before 1.16.5 some configurations of ReverseProxy (from net/http/httputil) result in a situation where an attacker is able to drop arbitrary headers. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore
msrc
CVE-2021-27918HIGHCVSS 7.52021-03-09
CVE-2021-27918 [HIGH] CWE-835 encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the middle of an element. This can occur in the Decode D encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the middle of an element. This can occur in the Decode DecodeElement or Skip method. FAQ: Is Azure Linux the only Microsoft
msrc
CVE-2021-3115HIGHCVSS 7.52021-01-12
CVE-2021-3115 [HIGH] CWE-427 Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example cg Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example cgo can execute a gcc program from an untrusted download). FAQ: Is Azur
msrc
CVE-2021-3114MEDIUMCVSS 6.52021-01-12
CVE-2021-3114 [MEDIUM] CWE-682 In Go before 1.14.14 and 1.15.x before 1.15.7 crypto/elliptic/p224.go can generate incorrect outputs related to an underflow of the lowest limb during the final complete reduction in the P-224 field. In Go before 1.14.14 and 1.15.x before 1.15.7 crypto/elliptic/p224.go can generate incorrect outputs related to an underflow of the lowest limb during the final complete reduction in the P-224 field. FAQ: Is Azure Linux the only Microsoft product that includes this op
msrc