Msrc Cbl Mariner 2.0 X64 vulnerabilities
1,677 known vulnerabilities affecting msrc/cbl_mariner_2.0_x64.
Total CVEs
1,677
CISA KEV
8
actively exploited
Public exploits
16
Exploited in wild
8
Severity breakdown
CRITICAL92HIGH705MEDIUM842LOW38
Vulnerabilities
Page 30 of 84
CVE-2024-33602HIGHCVSS 8.62024-05-14
CVE-2024-33602 [HIGH] CWE-466 nscd: netgroup cache assumes NSS callback uses in-buffer strings
nscd: netgroup cache assumes NSS callback uses in-buffer strings
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libr
msrc
CVE-2024-27018HIGHCVSS 7.82024-05-14
CVE-2024-27018 [HIGH] netfilter: br_netfilter: skip conntrack input hook for promisc packets
netfilter: br_netfilter: skip conntrack input hook for promisc packets
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source
msrc
CVE-2024-26933HIGHCVSS 7.82024-05-14
CVE-2024-26933 [HIGH] CWE-667 USB: core: Fix deadlock in port "disable" sysfs attribute
USB: core: Fix deadlock in port "disable" sysfs attribute
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with whi
msrc
CVE-2024-34251HIGHCVSS 7.52024-05-14
CVE-2024-34251 [HIGH] CVE-2024-34251: NIST NVD Details: https://nvd
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2024-34251
Mariner: Mariner
[email protected]: [email protected]
Customer Action Required: Yes
Exploit Status: DOS:N/A
Remediation: fluent-bit
Reference: https://nvd.nist.gov/vuln/detail/CVE-2024-34251
msrc
CVE-2024-32620HIGHCVSS 7.42024-05-14
CVE-2024-32620 [HIGH] CWE-122 HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c resulting in the corruption of the instruction pointer.
HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c resulting in the corruption of the instruction pointer.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of
msrc
CVE-2024-32614HIGHCVSS 8.82024-05-14
CVE-2024-32614 [HIGH] CWE-125 HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.
HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source
msrc
CVE-2024-32605HIGHCVSS 8.82024-05-14
CVE-2024-32605 [HIGH] CWE-122 HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c).
HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers
msrc
CVE-2024-3727HIGHCVSS 8.32024-05-14
CVE-2024-3727 [HIGH] CWE-354 Containers/image: digest type does not guarantee valid type
Containers/image: digest type does not guarantee valid type
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with
msrc
CVE-2024-29162HIGHCVSS 7.42024-05-14
CVE-2024-29162 [HIGH] CWE-122 HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read resulting in denial of service or potential code execution.
HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read resulting in denial of service or potential code execution.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers
msrc
CVE-2024-34459HIGHCVSS 7.52024-05-14
CVE-2024-34459 [HIGH] CWE-122 An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext i
An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c.
FAQ: Is Azure Linux the only Microsoft product that inc
msrc
CVE-2024-2410HIGHCVSS 7.62024-05-14
CVE-2024-2410 [HIGH] CWE-416 Use after free in C++ protobuf
Use after free in C++ protobuf
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to tr
msrc
CVE-2024-29160HIGHCVSS 7.42024-05-14
CVE-2024-29160 [HIGH] CWE-122 HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
FAQ: Is Azure Linux the only Microsoft product that includes this open-so
msrc
CVE-2024-29165HIGHCVSS 7.42024-05-14
CVE-2024-29165 [HIGH] CWE-122 HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32 resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32 resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is th
msrc
CVE-2024-29158HIGHCVSS 7.42024-05-14
CVE-2024-29158 [HIGH] CWE-122 HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is ther
msrc
CVE-2024-5564HIGHCVSS 8.12024-05-14
CVE-2024-5564 [HIGH] CWE-120 Libndp: buffer overflow in route information length field
Libndp: buffer overflow in route information length field
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with whic
msrc
CVE-2024-33877HIGHCVSS 8.82024-05-14
CVE-2024-33877 [HIGH] CWE-122 HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c.
HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date w
msrc
CVE-2024-34069HIGHCVSS 7.5PoC2024-05-14
CVE-2024-34069 [HIGH] CWE-352 Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command execution
Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command execution
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to
msrc
CVE-2024-29163HIGHCVSS 7.42024-05-14
CVE-2024-29163 [HIGH] CWE-122 HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore
msrc
CVE-2024-26961HIGHCVSS 7.82024-05-14
CVE-2024-26961 [HIGH] CWE-416 mac802154: fix llsec key resources release in mac802154_llsec_key_del
mac802154: fix llsec key resources release in mac802154_llsec_key_del
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open s
msrc
CVE-2024-32618HIGHCVSS 7.42024-05-14
CVE-2024-32618 [HIGH] CWE-122 HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c resulting in the corruption of the instruction pointer.
HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c resulting in the corruption of the instruction pointer.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
msrc