Msrc Cbl Mariner 1.0 X64 vulnerabilities
808 known vulnerabilities affecting msrc/cbl_mariner_1.0_x64.
Total CVEs
808
CISA KEV
2
actively exploited
Public exploits
17
Exploited in wild
1
Severity breakdown
CRITICAL40HIGH349MEDIUM383LOW36
Vulnerabilities
Page 9 of 41
CVE-2022-43551HIGHCVSS 7.52022-12-13
CVE-2022-43551 [HIGH] CWE-319 A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support curl can be instructed to use HTTPS instead of using an insecure clear-t
A vulnerability exists in curl Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commit
msrc
CVE-2022-42898HIGHCVSS 8.82022-12-13
CVE-2022-42898 [HIGH] CWE-190 PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC kadmind or a GSS or Kerberos application server) on
PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC kadmind or a GSS or Kerberos application server) on 32-bit platforms (which have a resultant heap-based buffer overflow)
msrc
CVE-2021-4235MEDIUMCVSS 5.52022-12-13
CVE-2021-4235 [MEDIUM] Denial of service in gopkg.in/yaml.v2
Denial of service in gopkg.in/yaml.v2
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committ
msrc
CVE-2022-41717MEDIUMCVSS 5.32022-12-13
CVE-2022-41717 [MEDIUM] CWE-770 Excessive memory growth in net/http and golang.org/x/net/http2
Excessive memory growth in net/http and golang.org/x/net/http2
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source librar
msrc
CVE-2022-42919HIGHCVSS 7.82022-11-08
CVE-2022-42919 [HIGH] Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library when used with the forkserver start me
Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library when used with the forkserver start method on Linux allows pickles to be deserialized from any user in the same mac
msrc
CVE-2022-45934HIGHCVSS 7.82022-11-08
CVE-2022-45934 [HIGH] CWE-190 An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets.
An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
msrc
CVE-2022-3872HIGHCVSS 8.62022-11-08
CVE-2022-3872 [HIGH] CWE-193 An off-by-one read/write issue was found in the SDHCI device of QEMU. It occurs when reading/writing the Buffer Data Port Register in sdhci_read_dataport and sdhci_write_dataport respectively if data_
An off-by-one read/write issue was found in the SDHCI device of QEMU. It occurs when reading/writing the Buffer Data Port Register in sdhci_read_dataport and sdhci_write_dataport respectively if data_count == block_size. A malicious guest could use this flaw to crash th
msrc
CVE-2022-41916HIGHCVSS 7.52022-11-08
CVE-2022-41916 [MEDIUM] CWE-193 Read one byte past a buffer when normalizing Unicode
Read one byte past a buffer when normalizing Unicode
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the d
msrc
CVE-2022-3821MEDIUMCVSS 5.52022-11-08
CVE-2022-3821 [MEDIUM] CWE-193 An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_
An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan() leading to a Denial of Service.
FAQ: Is Azure Linux the
msrc
CVE-2022-4127MEDIUMCVSS 5.52022-11-08
CVE-2022-4127 [MEDIUM] CWE-476 A NULL pointer dereference issue was discovered in the Linux kernel in io_files_update_with_index_alloc. A local user could use this flaw to potentially crash the system causing a denial of service.
A NULL pointer dereference issue was discovered in the Linux kernel in io_files_update_with_index_alloc. A local user could use this flaw to potentially crash the system causing a denial of service.
FAQ: Is Azure Linux the only Microsoft product that includes this open
msrc
CVE-2022-45869MEDIUMCVSS 5.52022-11-08
CVE-2022-45869 [MEDIUM] CWE-362 A race condition in the x86 KVM subsystem in the Linux kernel through 6.1-rc6 allows guest OS users to cause a denial of service (host OS crash or host OS memory corruption) when nested virtualisation
A race condition in the x86 KVM subsystem in the Linux kernel through 6.1-rc6 allows guest OS users to cause a denial of service (host OS crash or host OS memory corruption) when nested virtualisation and the TDP MMU are enabled.
FAQ: Is Azure Linux the only Microso
msrc
CVE-2022-37454CRITICALCVSS 9.82022-10-11
CVE-2022-37454 [CRITICAL] CWE-190 The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic
The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.
FAQ: I
msrc
CVE-2022-42915HIGHCVSS 8.12022-10-11
CVE-2022-42915 [HIGH] CWE-415 curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL it sets up the connection to the remote server by issuing a CONNECT request to the prox
curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL it sets up the connection to the remote server by issuing a CONNECT request to the proxy and then tunnels the rest of the protocol through. An HTTP proxy mi
msrc
CVE-2022-42916HIGHCVSS 7.52022-10-11
CVE-2022-42916 [HIGH] CWE-319 In curl before 7.86.0 the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support curl can be instructed to use HTTPS directly (instead of using an insecure cleartext H
In curl before 7.86.0 the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL. This mechanism could
msrc
CVE-2022-29503CRITICALCVSS 9.82022-09-13
CVE-2022-29503 [CRITICAL] CWE-770 A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create t
A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger this vulnerability.
FAQ: Is Azure Linux the on
msrc
CVE-2022-2962HIGHCVSS 7.82022-09-13
CVE-2022-2962 [HIGH] CWE-662 A DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descriptor or copies the rx/tx frame it doesn't check whether the destination address is
A DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descriptor or copies the rx/tx frame it doesn't check whether the destination address is its own MMIO address. This can cause the device to trigger MMIO handl
msrc
CVE-2022-38177HIGHCVSS 7.52022-09-13
CVE-2022-38177 [HIGH] CWE-401 Memory leak in ECDSA DNSSEC verification code
Memory leak in ECDSA DNSSEC verification code
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is compose
msrc
CVE-2020-10735HIGHCVSS 7.52022-09-13
CVE-2020-10735 [HIGH] CWE-704 A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases when using int("text") a system could take 50ms to parse an int string with 100000 digits and 5s for 100
A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases when using int("text") a system could take 50ms to parse an int string with 100000 digits and 5s for 1000000 digits (float decimal int.from_bytes() and int() for binary base
msrc
CVE-2022-40320HIGHCVSS 8.82022-09-13
CVE-2022-40320 [HIGH] CWE-125 cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read.
cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most sec
msrc
CVE-2022-38178HIGHCVSS 7.52022-09-13
CVE-2022-38178 [HIGH] CWE-401 Memory leaks in EdDSA DNSSEC verification code
Memory leaks in EdDSA DNSSEC verification code
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is compo
msrc