Msrc Cbl Mariner 1.0 X64 vulnerabilities
808 known vulnerabilities affecting msrc/cbl_mariner_1.0_x64.
Total CVEs
808
CISA KEV
2
actively exploited
Public exploits
17
Exploited in wild
1
Severity breakdown
CRITICAL40HIGH349MEDIUM383LOW36
Vulnerabilities
Page 41 of 41
CVE-2016-6664HIGHCVSS 7.0PoC2016-12-13
CVE-2016-6664 [HIGH] CWE-59 mysqld_safe in Oracle MySQL through 5.5.51 5.6.x through 5.6.32 and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2 5.6.x before 5.6.32-78-1 and 5.7.x before 5.7.14-8; and Percona Xtr
mysqld_safe in Oracle MySQL through 5.5.51 5.6.x through 5.6.32 and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2 5.6.x before 5.6.32-78-1 and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0 5.6.x before 5.6.32-25.17 and 5.7.x befo
msrc
CVE-2016-9296HIGHCVSS 7.52016-11-08
CVE-2016-9296 [HIGH] CWE-476 A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable folders.PackPositions in function CInArchive::ReadAndDecodePackedStreams
A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable folders.PackPositions in function CInArchive::ReadAndDecodePackedStreams in CPP/7zip/Archive/7z/7zIn.cpp as used in the 7z.so library and in 7z
msrc
CVE-2016-7161CRITICALCVSS 9.82016-10-11
CVE-2016-7161 [CRITICAL] CWE-787 Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large ethlite packet.
Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large ethlite packet.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source
msrc
CVE-2015-5738HIGHCVSS 7.52016-07-12
CVE-2015-5738 [HIGH] CWE-200 The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perfect Forward Secrecy (PFS) makes it easier for remote
The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perfect Forward Secrecy (PFS) makes it easier for remote attackers to obtain private RSA keys by conducting a Lenstra side-cha
msrc
CVE-2016-3697HIGHCVSS 7.82016-06-14
CVE-2016-3697 [HIGH] CWE-264 libcontainer/user/user.go in runC before 0.1.0 as used in Docker before 1.11.2 improperly treats a numeric UID as a potential username which allows local users to gain privileges via a numeric usernam
libcontainer/user/user.go in runC before 0.1.0 as used in Docker before 1.11.2 improperly treats a numeric UID as a potential username which allows local users to gain privileges via a numeric username in the password file in a container.
FAQ: Is Azure Linux the only M
msrc
CVE-2016-3189MEDIUMCVSS 6.52016-06-14
CVE-2016-3189 [MEDIUM] Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file related to block ends set to before the start of the b
Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file related to block ends set to before the start of the block.
FAQ: Is Azure Linux the only Microsoft product that includes this ope
msrc
CVE-2015-8863CRITICALCVSS 9.82016-05-10
CVE-2015-8863 [CRITICAL] CWE-119 Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number which triggers a heap-based buffer overflow.
Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number which triggers a heap-based buffer overflow.
FAQ: Is Azure Linux the only Microsoft product that includes this op
msrc
CVE-2016-4074HIGHCVSS 7.52016-05-10
CVE-2016-4074 [HIGH] CWE-770 The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file. This issue has been fixed in jq 1.6_rc1-r0.
The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file. This issue has been fixed in jq 1.6_rc1-r0.
FAQ: Is Azure Linux the only Microsoft product that includes this open
msrc
← Previous41 / 41