Msrc Cbl Mariner 2.0 X64 vulnerabilities

1,677 known vulnerabilities affecting msrc/cbl_mariner_2.0_x64.

Total CVEs
1,677
CISA KEV
8
actively exploited
Public exploits
16
Exploited in wild
8
Severity breakdown
CRITICAL92HIGH705MEDIUM842LOW38

Vulnerabilities

Page 47 of 84
CVE-2022-28735HIGHCVSS 7.82023-07-11
CVE-2022-28735 [MEDIUM] The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain. FAQ: Is Azure Linux the only Microso
msrc
CVE-2023-4004HIGHCVSS 7.82023-07-11
CVE-2023-4004 [HIGH] CWE-416 Kernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove() Kernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove() FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent a
msrc
CVE-2023-3773MEDIUMCVSS 4.42023-07-11
CVE-2023-3773 [MEDIUM] CWE-125 Kernel: xfrm: out-of-bounds read of xfrma_mtimer_thresh nlattr Kernel: xfrm: out-of-bounds read of xfrma_mtimer_thresh nlattr FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source librari
msrc
CVE-2023-39128MEDIUMCVSS 5.52023-07-11
CVE-2023-39128 [MEDIUM] CWE-787 GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a stack overflow via the function ada_decode at /gdb/ada-lang.c. GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a stack overflow via the function ada_decode at /gdb/ada-lang.c. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azur
msrc
CVE-2023-3863MEDIUMCVSS 4.12023-07-11
CVE-2023-3863 [MEDIUM] CWE-416 Use-after-free in nfc_llcp_find_loca in net/nfc/llcp_core.c Use-after-free in nfc_llcp_find_loca in net/nfc/llcp_core.c FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries wit
msrc
CVE-2022-28737MEDIUMCVSS 6.52023-07-11
CVE-2022-28737 [MEDIUM] CWE-787 There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep
msrc
CVE-2023-3817MEDIUMCVSS 5.32023-07-11
CVE-2023-3817 [MEDIUM] CWE-834 Excessive time spent checking DH q parameter value Excessive time spent checking DH q parameter value FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro
msrc
CVE-2023-3772MEDIUMCVSS 4.42023-07-11
CVE-2023-3772 [MEDIUM] CWE-476 Kernel: xfrm: null pointer dereference in xfrm_update_ae_params() Kernel: xfrm: null pointer dereference in xfrm_update_ae_params() FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source l
msrc
CVE-2023-38409MEDIUMCVSS 5.52023-07-11
CVE-2023-38409 [MEDIUM] CWE-362 An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because an assignment occurs only for the first vc the fbcon_registered_fb and fbcon_di An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because an assignment occurs only for the first vc the fbcon_registered_fb and fbcon_display arrays can be desynchronized in fbcon_mode_deleted (the con2f
msrc
CVE-2023-3446MEDIUMCVSS 5.32023-07-11
CVE-2023-3446 [MEDIUM] CWE-1333 Excessive time spent checking DH keys and parameters Excessive time spent checking DH keys and parameters FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the d
msrc
CVE-2023-33952MEDIUMCVSS 6.72023-07-11
CVE-2023-33952 [MEDIUM] CWE-415 Kernel: vmwgfx: double free within the handling of vmw_buffer_object objects Kernel: vmwgfx: double free within the handling of vmw_buffer_object objects FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versio
msrc
CVE-2023-39130MEDIUMCVSS 5.52023-07-11
CVE-2023-39130 [MEDIUM] CWE-787 GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap buffer overflow via the function pe_as16() at /gdb/coff-pe-read.c. GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap buffer overflow via the function pe_as16() at /gdb/coff-pe-read.c. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choo
msrc
CVE-2023-39129MEDIUMCVSS 5.52023-07-11
CVE-2023-39129 [MEDIUM] CWE-416 GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap use after free via the function add_pe_exported_sym() at /gdb/coff-pe-read.c. GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap use after free via the function add_pe_exported_sym() at /gdb/coff-pe-read.c. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to
msrc
CVE-2023-33951MEDIUMCVSS 5.32023-07-11
CVE-2023-33951 [MEDIUM] CWE-362 Kernel: vmwgfx: race condition leading to information disclosure vulnerability Kernel: vmwgfx: race condition leading to information disclosure vulnerability FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure ve
msrc
CVE-2023-2860MEDIUMCVSS 4.42023-07-11
CVE-2023-2860 [MEDIUM] CWE-125 Out-of-bounds read when setting hmac data Out-of-bounds read when setting hmac data FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Micr
msrc
CVE-2023-2975MEDIUMCVSS 5.32023-07-11
CVE-2023-2975 [MEDIUM] CWE-354 AES-SIV implementation ignores empty associated data entries AES-SIV implementation ignores empty associated data entries FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries w
msrc
CVE-2023-29404CRITICALCVSS 9.82023-06-13
CVE-2023-29404 [CRITICAL] CWE-94 Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions
msrc
CVE-2023-29402CRITICALCVSS 9.82023-06-13
CVE-2023-29402 [CRITICAL] CWE-94 Code injection via go command with cgo in cmd/go Code injection via go command with cgo in cmd/go FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro i
msrc
CVE-2023-3111HIGHCVSS 7.82023-06-13
CVE-2023-3111 [HIGH] CWE-416 A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calli A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag(). FAQ: Is Azure Linux the only Microsoft produ
msrc
CVE-2023-3141HIGHCVSS 7.12023-06-13
CVE-2023-3141 [HIGH] CWE-416 A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect possibly A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect possibly leading to a kernel information leak. FAQ: Is Azure Linux the only Mi
msrc