Msrc Cbl2 Hvloader 1.0.1-6 On Cbl Mariner 2.0 vulnerabilities
11 known vulnerabilities affecting msrc/cbl2_hvloader_1.0.1-6_on_cbl_mariner_2.0.
Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
HIGH3MEDIUM8
Vulnerabilities
Page 1 of 1
CVE-2024-4741HIGHCVSS 7.5Exploited2024-11-12
CVE-2024-4741 [HIGH] CWE-416 Use After Free with SSL_free_buffers
Use After Free with SSL_free_buffers
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is com
msrc
CVE-2024-4603MEDIUMCVSS 5.32024-05-14
CVE-2024-4603 [MEDIUM] CWE-606 Excessive time spent checking DSA keys and parameters
Excessive time spent checking DSA keys and parameters
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the
msrc
CVE-2023-6237MEDIUMCVSS 5.92024-04-09
CVE-2023-6237 [MEDIUM] CWE-606 Excessive time spent checking invalid RSA public keys
Excessive time spent checking invalid RSA public keys
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the
msrc
CVE-2024-2511MEDIUMCVSS 5.92024-04-09
CVE-2024-2511 [MEDIUM] CWE-1325 Unbounded memory growth with session handling in TLSv1.3
Unbounded memory growth with session handling in TLSv1.3
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with whi
msrc
CVE-2024-28960HIGHCVSS 8.22024-03-12
CVE-2024-28960 [HIGH] CWE-284 An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0 and Mbed Crypto. The PSA Crypto API mishandles shared memory.
An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0 and Mbed Crypto. The PSA Crypto API mishandles shared memory.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the m
msrc
CVE-2024-23775HIGHCVSS 7.52024-01-09
CVE-2024-23775 [HIGH] Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2 allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension().
Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2 allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension().
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerabi
msrc
CVE-2024-23170MEDIUMCVSS 5.52024-01-09
CVE-2024-23170 [MEDIUM] CWE-203 An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations.
An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choo
msrc
CVE-2023-6129MEDIUMCVSS 6.52024-01-09
CVE-2023-6129 [MEDIUM] CWE-787 POLY1305 MAC implementation corrupts vector registers on PowerPC
POLY1305 MAC implementation corrupts vector registers on PowerPC
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source lib
msrc
CVE-2023-3446MEDIUMCVSS 5.32023-07-11
CVE-2023-3446 [MEDIUM] CWE-1333 Excessive time spent checking DH keys and parameters
Excessive time spent checking DH keys and parameters
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the d
msrc
CVE-2023-2975MEDIUMCVSS 5.32023-07-11
CVE-2023-2975 [MEDIUM] CWE-354 AES-SIV implementation ignores empty associated data entries
AES-SIV implementation ignores empty associated data entries
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries w
msrc
CVE-2023-0466MEDIUMCVSS 5.32023-03-14
CVE-2023-0466 [MEDIUM] CWE-295 Certificate policy check not enabled
Certificate policy check not enabled
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is c
msrc