Msrc Cbl Mariner 1.0 Arm vulnerabilities

808 known vulnerabilities affecting msrc/cbl_mariner_1.0_arm.

Total CVEs
808
CISA KEV
2
actively exploited
Public exploits
17
Exploited in wild
1
Severity breakdown
CRITICAL40HIGH349MEDIUM383LOW36

Vulnerabilities

Page 3 of 41
CVE-2023-3316MEDIUMCVSS 6.52023-06-13
CVE-2023-3316 [MEDIUM] CWE-476 A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path that requires permissions like /dev/null) while specifying zones. A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path that requires permissions like /dev/null) while specifying zones. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore
msrc
CVE-2023-26965MEDIUMCVSS 5.52023-06-13
CVE-2023-26965 [MEDIUM] CWE-787 loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image. loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the
msrc
CVE-2023-26966MEDIUMCVSS 5.52023-06-13
CVE-2023-26966 [MEDIUM] CWE-120 libtiff 4.5.0 is vulnerable to Buffer Overflow in uv_encode() when libtiff reads a corrupted little-endian TIFF file and specifies the output to be big-endian. libtiff 4.5.0 is vulnerable to Buffer Overflow in uv_encode() when libtiff reads a corrupted little-endian TIFF file and specifies the output to be big-endian. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
msrc
CVE-2023-3359MEDIUMCVSS 5.52023-06-13
CVE-2023-3359 [MEDIUM] CWE-476 An issue was discovered in the Linux kernel brcm_nvram_parse in drivers/nvmem/brcm_nvram.c. Lacks for the check of the return value of kzalloc() can cause the NULL Pointer Dereference. An issue was discovered in the Linux kernel brcm_nvram_parse in drivers/nvmem/brcm_nvram.c. Lacks for the check of the return value of kzalloc() can cause the NULL Pointer Dereference. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is there
msrc
CVE-2023-2908MEDIUMCVSS 5.52023-06-13
CVE-2023-2908 [MEDIUM] CWE-476 Libtiff: null pointer dereference in tif_dir.c Libtiff: null pointer dereference in tif_dir.c FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is comp
msrc
CVE-2023-32763HIGHCVSS 7.52023-05-09
CVE-2023-32763 [HIGH] CWE-120 An issue was discovered in Qt before 5.15.15 6.x before 6.2.9 and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered a QTextLayout buffer overflow can be triggered. An issue was discovered in Qt before 5.15.15 6.x before 6.2.9 and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered a QTextLayout buffer overflow can be triggered. FAQ: Is Azure Linux the only Microsoft product that includes this ope
msrc
CVE-2023-32067HIGHCVSS 7.52023-05-09
CVE-2023-32067 [HIGH] CWE-400 0-byte UDP payload DoS in c-ares 0-byte UDP payload DoS in c-ares FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed
msrc
CVE-2023-32233HIGHCVSS 7.82023-05-09
CVE-2023-32233 [HIGH] CWE-416 In the Linux kernel through 6.3.1 a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged loc In the Linux kernel through 6.3.1 a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous se
msrc
CVE-2023-33288MEDIUMCVSS 4.72023-05-09
CVE-2023-33288 [MEDIUM] CWE-416 An issue was discovered in the Linux kernel before 6.2.9. A use-after-free was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It could allow a local attacker to crash the system du An issue was discovered in the Linux kernel before 6.2.9. A use-after-free was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It could allow a local attacker to crash the system due to a race condition. FAQ: Is Azure Linux the only Microsoft prod
msrc
CVE-2023-32269MEDIUMCVSS 6.72023-05-09
CVE-2023-32269 [MEDIUM] CWE-416 An issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c there is a use-after-free because accept is also allowed for a successfully connected AF_NETROM socket. However in An issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c there is a use-after-free because accept is also allowed for a successfully connected AF_NETROM socket. However in order for an attacker to exploit this the system must have netrom r
msrc
CVE-2023-2650MEDIUMCVSS 6.52023-05-09
CVE-2023-2650 [MEDIUM] CWE-770 Possible DoS translating ASN.1 object identifiers Possible DoS translating ASN.1 object identifiers FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro i
msrc
CVE-2023-1859MEDIUMCVSS 4.72023-05-09
CVE-2023-1859 [MEDIUM] CWE-416 A use-after-free flaw was found in xen_9pfs_front_removet in net/9p/trans_xen.c in Xen transport for 9pfs in the Linux Kernel. This flaw could allow a local attacker to crash the system due to a race A use-after-free flaw was found in xen_9pfs_front_removet in net/9p/trans_xen.c in Xen transport for 9pfs in the Linux Kernel. This flaw could allow a local attacker to crash the system due to a race problem possibly leading to a kernel information leak. FAQ: Is Azur
msrc
CVE-2023-0459MEDIUMCVSS 5.52023-05-09
CVE-2023-0459 [MEDIUM] CWE-763 Copy_from_user Spectre-V1 Gadget in Linux Kernel Copy_from_user Spectre-V1 Gadget in Linux Kernel FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is
msrc
CVE-2023-34256MEDIUMCVSS 5.52023-05-09
CVE-2023-34256 [MEDIUM] CWE-125 An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from fs/ext4/super.c because ext4_group_desc_csum does not properly check a An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from fs/ext4/super.c because ext4_group_desc_csum does not properly check an offset. NOTE: this is disputed by third parties because the kerne
msrc
CVE-2023-2731MEDIUMCVSS 5.52023-05-09
CVE-2023-2731 [MEDIUM] CWE-476 A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file res
msrc
CVE-2023-1195MEDIUMCVSS 5.52023-05-09
CVE-2023-1195 [MEDIUM] CWE-416 A use-after-free flaw was found in reconn_set_ipaddr_from_hostname in fs/cifs/connect.c in the Linux kernel. The issue occurs when it forgets to set the free pointer server->hostname to NULL leading t A use-after-free flaw was found in reconn_set_ipaddr_from_hostname in fs/cifs/connect.c in the Linux kernel. The issue occurs when it forgets to set the free pointer server->hostname to NULL leading to an invalid pointer request. FAQ: Is Azure Linux the only Microsof
msrc
CVE-2023-32762MEDIUMCVSS 5.32023-05-09
CVE-2023-32762 [MEDIUM] An issue was discovered in Qt before 5.15.14 6.x before 6.2.9 and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header allowing unencrypted conne An issue was discovered in Qt before 5.15.14 6.x before 6.2.9 and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header allowing unencrypted connections to be established even when explicitly prohibited by the server. Thi
msrc
CVE-2023-33203MEDIUMCVSS 6.42023-05-09
CVE-2023-33203 [MEDIUM] CWE-362 The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker unplugs an emac based device. The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker unplugs an emac based device. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library a
msrc
CVE-2023-32681MEDIUMCVSS 6.12023-05-09
CVE-2023-32681 [MEDIUM] CWE-200 Unintended leak of Proxy-Authorization header in requests Unintended leak of Proxy-Authorization header in requests FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with w
msrc
CVE-2023-28322LOWCVSS 3.72023-05-09
CVE-2023-28322 [LOW] CWE-200 An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send even when t An information disclosure vulnerability exists in curl Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Lin
msrc