Msrc Cbl Mariner 2.0 Arm vulnerabilities
1,677 known vulnerabilities affecting msrc/cbl_mariner_2.0_arm.
Total CVEs
1,677
CISA KEV
8
actively exploited
Public exploits
16
Exploited in wild
8
Severity breakdown
CRITICAL92HIGH705MEDIUM842LOW38
Vulnerabilities
Page 40 of 84
CVE-2024-20967MEDIUMCVSS 5.52024-01-09
CVE-2024-20967 [MEDIUM] Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerab
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protoc
msrc
CVE-2023-6915MEDIUMCVSS 5.52024-01-09
CVE-2023-6915 [MEDIUM] CWE-476 Kernel: null pointer dereference vulnerability in ida_free in lib/idr.c
Kernel: null pointer dereference vulnerability in ida_free in lib/idr.c
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the o
msrc
CVE-2023-45236MEDIUMCVSS 5.82024-01-09
CVE-2023-45236 [MEDIUM] CWE-338 Predictable TCP ISNs in EDK II Network Package
Predictable TCP ISNs in EDK II Network Package
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is com
msrc
CVE-2024-20961MEDIUMCVSS 6.52024-01-09
CVE-2024-20961 [MEDIUM] Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerabil
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols
msrc
CVE-2023-45229MEDIUMCVSS 6.52024-01-09
CVE-2023-45229 [MEDIUM] CWE-125 Out-of-Bounds Read in EDK II Network Package
Out-of-Bounds Read in EDK II Network Package
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is compose
msrc
CVE-2023-45231MEDIUMCVSS 6.52024-01-09
CVE-2023-45231 [MEDIUM] CWE-125 Out-of-Bounds Read in EDK II Network Package
Out-of-Bounds Read in EDK II Network Package
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is compose
msrc
CVE-2024-0727MEDIUMCVSS 5.52024-01-09
CVE-2024-0727 [MEDIUM] CWE-476 PKCS12 Decoding crashes
PKCS12 Decoding crashes
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency i
msrc
CVE-2024-20963MEDIUMCVSS 6.52024-01-09
CVE-2024-20963 [MEDIUM] Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multipl
msrc
CVE-2024-20965MEDIUMCVSS 4.92024-01-09
CVE-2024-20965 [MEDIUM] Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerabil
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocol
msrc
CVE-2024-23170MEDIUMCVSS 5.52024-01-09
CVE-2024-23170 [MEDIUM] CWE-203 An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations.
An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choo
msrc
CVE-2023-40550MEDIUMCVSS 5.52024-01-09
CVE-2023-40550 [MEDIUM] CWE-125 Shim: out-of-bound read in verify_buffer_sbat()
Shim: out-of-bound read in verify_buffer_sbat()
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is c
msrc
CVE-2023-6129MEDIUMCVSS 6.52024-01-09
CVE-2023-6129 [MEDIUM] CWE-787 POLY1305 MAC implementation corrupts vector registers on PowerPC
POLY1305 MAC implementation corrupts vector registers on PowerPC
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source lib
msrc
CVE-2024-20977MEDIUMCVSS 6.52024-01-09
CVE-2024-20977 [MEDIUM] Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerabil
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols
msrc
CVE-2023-49295MEDIUMCVSS 6.42024-01-09
CVE-2023-49295 [MEDIUM] CWE-400 quic-go's path validation mechanism can cause denial of service
quic-go's path validation mechanism can cause denial of service
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libr
msrc
CVE-2024-20971MEDIUMCVSS 4.92024-01-09
CVE-2024-20971 [MEDIUM] Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerabil
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocol
msrc
CVE-2024-20981MEDIUMCVSS 4.92024-01-09
CVE-2024-20981 [MEDIUM] Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability al
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to c
msrc
CVE-2023-40551MEDIUMCVSS 5.12024-01-09
CVE-2023-40551 [MEDIUM] CWE-125 Shim: out of bounds read when parsing mz binaries
Shim: out of bounds read when parsing mz binaries
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro
msrc
CVE-2024-0607MEDIUMCVSS 6.62024-01-09
CVE-2024-0607 [MEDIUM] CWE-229 Kernel: nf_tables: pointer math issue in nft_byteorder_eval()
Kernel: nf_tables: pointer math issue in nft_byteorder_eval()
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries
msrc
CVE-2024-20973MEDIUMCVSS 6.52024-01-09
CVE-2024-20973 [MEDIUM] Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerabil
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols
msrc
CVE-2023-40546MEDIUMCVSS 5.52024-01-09
CVE-2023-40546 [MEDIUM] CWE-476 Shim: out-of-bounds read printing error messages
Shim: out-of-bounds read printing error messages
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is
msrc