Msrc Cbl Mariner 2.0 X64 vulnerabilities
1,677 known vulnerabilities affecting msrc/cbl_mariner_2.0_x64.
Total CVEs
1,677
CISA KEV
8
actively exploited
Public exploits
16
Exploited in wild
8
Severity breakdown
CRITICAL92HIGH705MEDIUM842LOW38
Vulnerabilities
Page 49 of 84
CVE-2023-26966MEDIUMCVSS 5.52023-06-13
CVE-2023-26966 [MEDIUM] CWE-120 libtiff 4.5.0 is vulnerable to Buffer Overflow in uv_encode() when libtiff reads a corrupted little-endian TIFF file and specifies the output to be big-endian.
libtiff 4.5.0 is vulnerable to Buffer Overflow in uv_encode() when libtiff reads a corrupted little-endian TIFF file and specifies the output to be big-endian.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
msrc
CVE-2023-3359MEDIUMCVSS 5.52023-06-13
CVE-2023-3359 [MEDIUM] CWE-476 An issue was discovered in the Linux kernel brcm_nvram_parse in drivers/nvmem/brcm_nvram.c. Lacks for the check of the return value of kzalloc() can cause the NULL Pointer Dereference.
An issue was discovered in the Linux kernel brcm_nvram_parse in drivers/nvmem/brcm_nvram.c. Lacks for the check of the return value of kzalloc() can cause the NULL Pointer Dereference.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is there
msrc
CVE-2023-2908MEDIUMCVSS 5.52023-06-13
CVE-2023-2908 [MEDIUM] CWE-476 Libtiff: null pointer dereference in tif_dir.c
Libtiff: null pointer dereference in tif_dir.c
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is comp
msrc
CVE-2023-33204HIGHCVSS 7.82023-05-09
CVE-2023-33204 [HIGH] CWE-190 sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377.
sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this v
msrc
CVE-2023-2953HIGHCVSS 7.52023-05-09
CVE-2023-2953 [HIGH] CWE-476 A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux dis
msrc
CVE-2023-32763HIGHCVSS 7.52023-05-09
CVE-2023-32763 [HIGH] CWE-120 An issue was discovered in Qt before 5.15.15 6.x before 6.2.9 and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered a QTextLayout buffer overflow can be triggered.
An issue was discovered in Qt before 5.15.15 6.x before 6.2.9 and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered a QTextLayout buffer overflow can be triggered.
FAQ: Is Azure Linux the only Microsoft product that includes this ope
msrc
CVE-2023-32067HIGHCVSS 7.52023-05-09
CVE-2023-32067 [HIGH] CWE-400 0-byte UDP payload DoS in c-ares
0-byte UDP payload DoS in c-ares
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed
msrc
CVE-2023-21102HIGHCVSS 7.82023-05-09
CVE-2023-21102 [HIGH] CWE-754 In __efi_rt_asm_wrapper of efi-rt-wrapper.S there is a possible bypass of shadow stack protection due to a logic error in the code. This could lead to local escalation of privilege with no additional
In __efi_rt_asm_wrapper of efi-rt-wrapper.S there is a possible bypass of shadow stack protection due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo
msrc
CVE-2023-32233HIGHCVSS 7.82023-05-09
CVE-2023-32233 [HIGH] CWE-416 In the Linux kernel through 6.3.1 a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged loc
In the Linux kernel through 6.3.1 a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous se
msrc
CVE-2023-28319HIGHCVSS 7.52023-05-09
CVE-2023-28319 [HIGH] CWE-416 A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails libcurl would free the memory
A use after free vulnerability exists in curl Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distr
msrc
CVE-2023-31490HIGHCVSS 7.52023-05-09
CVE-2023-31490 [HIGH] An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.
An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the
msrc
CVE-2023-32269MEDIUMCVSS 6.72023-05-09
CVE-2023-32269 [MEDIUM] CWE-416 An issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c there is a use-after-free because accept is also allowed for a successfully connected AF_NETROM socket. However in
An issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c there is a use-after-free because accept is also allowed for a successfully connected AF_NETROM socket. However in order for an attacker to exploit this the system must have netrom r
msrc
CVE-2023-28321MEDIUMCVSS 5.92023-05-09
CVE-2023-28321 [MEDIUM] CWE-295 An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl
An improper certificate validation vulnerability exists in curl Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use t
msrc
CVE-2023-2700MEDIUMCVSS 5.52023-05-09
CVE-2023-2700 [MEDIUM] CWE-401 A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtual
A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.
FAQ: I
msrc
CVE-2023-2650MEDIUMCVSS 6.52023-05-09
CVE-2023-2650 [MEDIUM] CWE-770 Possible DoS translating ASN.1 object identifiers
Possible DoS translating ASN.1 object identifiers
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro i
msrc
CVE-2023-1859MEDIUMCVSS 4.72023-05-09
CVE-2023-1859 [MEDIUM] CWE-416 A use-after-free flaw was found in xen_9pfs_front_removet in net/9p/trans_xen.c in Xen transport for 9pfs in the Linux Kernel. This flaw could allow a local attacker to crash the system due to a race
A use-after-free flaw was found in xen_9pfs_front_removet in net/9p/trans_xen.c in Xen transport for 9pfs in the Linux Kernel. This flaw could allow a local attacker to crash the system due to a race problem possibly leading to a kernel information leak.
FAQ: Is Azur
msrc
CVE-2023-0459MEDIUMCVSS 5.52023-05-09
CVE-2023-0459 [MEDIUM] CWE-763 Copy_from_user Spectre-V1 Gadget in Linux Kernel
Copy_from_user Spectre-V1 Gadget in Linux Kernel
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is
msrc
CVE-2023-34256MEDIUMCVSS 5.52023-05-09
CVE-2023-34256 [MEDIUM] CWE-125 An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from fs/ext4/super.c because ext4_group_desc_csum does not properly check a
An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from fs/ext4/super.c because ext4_group_desc_csum does not properly check an offset. NOTE: this is disputed by third parties because the kerne
msrc
CVE-2023-2731MEDIUMCVSS 5.52023-05-09
CVE-2023-2731 [MEDIUM] CWE-476 A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to
A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file res
msrc
CVE-2023-32762MEDIUMCVSS 5.32023-05-09
CVE-2023-32762 [MEDIUM] An issue was discovered in Qt before 5.15.14 6.x before 6.2.9 and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header allowing unencrypted conne
An issue was discovered in Qt before 5.15.14 6.x before 6.2.9 and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header allowing unencrypted connections to be established even when explicitly prohibited by the server. Thi
msrc