VYPR

Mesos

by Apache

Source repositories

CVEs (3)

  • CVE-2017-9790HigSep 29, 2017
    risk 0.42cvss 7.5epss 0.02

    When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev crashes if the request path is empty, because the parser assumes the request path always starts with '/'. A malicious…

  • CVE-2017-7687HigSep 29, 2017
    risk 0.42cvss 7.5epss 0.03

    When handling a decoding failure for a malformed URL path of an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev might crash because the code accidentally calls inappropriate function. A malicious actor can therefore…

  • CVE-2019-5736Feb 11, 2019
    risk 0.01cvss epss 0.59

    runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new…