VYPR

Vendor CVEs

Linux Foundation

All CVEs

558 total · sorted by risk
  • CVE-2024-31580MedApr 17, 2024
    risk 0.19cvss 4.0epss 0.00

    PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_functions.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2023-51699MedMar 15, 2024
    risk 0.19cvss 4.0epss 0.01

    Fluid is an open source Kubernetes-native Distributed Dataset Orchestrator and Accelerator for data-intensive applications. An OS command injection vulnerability within the Fluid project's JuicefsRuntime can potentially allow an authenticated user, who has the authority to…

  • CVE-2023-39348MedAug 28, 2023
    risk 0.19cvss 4.0epss 0.00

    Spinnaker is an open source, multi-cloud continuous delivery platform. Log output when updating GitHub status is improperly set to FULL always. It's recommended to apply the patch and rotate the GitHub token used for github status notifications. Given that this would output…

  • CVE-2022-31077MedJun 27, 2022
    risk 0.19cvss 4.0epss 0.01

    KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to hosts at the Edge. In affected versions a malicious message response from KubeEdge can crash the CSI Driver controller server by triggering a nil-pointer…

  • CVE-2024-22261LowJun 11, 2024
    risk 0.18cvss 2.7epss 0.00

    SQL-Injection in Harbor allows priviledge users to leak the task IDs

  • CVE-2026-24048LowJan 21, 2026
    risk 0.16cvss 3.5epss 0.00

    Backstage is an open framework for building developer portals, and @backstage/backend-defaults provides the default implementations and setup for a standard Backstage backend app. Prior to versions 0.12.2, 0.13.2, 0.14.1, and 0.15.0, the `FetchUrlReader` component, used by the…

  • CVE-2025-2149LowMar 10, 2025
    risk 0.16cvss 2.5epss 0.00

    A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of the argument scale/zero_point leads to improper initialization. The attack needs…

  • CVE-2024-45310LowSep 3, 2024
    risk 0.16cvss 3.6epss 0.00

    runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as well as 1.2.0-rc2 and earlier, can be tricked into creating empty files or directories in arbitrary locations in the host filesystem by sharing a volume between…

  • CVE-2024-20051LowApr 1, 2024
    risk 0.15cvss 2.3epss 0.00

    In flashc, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541758.

  • CVE-2025-3730LowApr 16, 2025
    risk 0.14cvss 3.3epss 0.00

    A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation leads to denial of service. An attack has to be approached locally. The exploit…

  • CVE-2026-29184LowMar 7, 2026
    risk 0.13cvss 2.0epss 0.00

    Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs. This issue has been patched in version 3.1.4.

  • CVE-2021-41190LowNov 17, 2021
    risk 0.13cvss 3.0epss 0.02

    The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document during push and pull…

  • CVE-2026-29185LowMar 7, 2026
    risk 0.11cvss 2.7epss 0.00

    Backstage is an open framework for building developer portals. Prior to version 1.20.1, a vulnerability in the SCM URL parsing used by Backstage integrations allowed path traversal sequences in encoded form to be included in file paths. When these URLs were processed by…

  • CVE-2023-32684LowMay 30, 2023
    risk 0.11cvss 2.7epss 0.00

    Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to version 0.16.0, a virtual machine instance with a malicious disk image could read a single file on the host filesystem, even when no filesystem is mounted from the host. The official…

  • CVE-2018-18264HigJan 3, 2019
    risk 0.06cvss 7.5epss 0.70

    Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.

  • CVE-2015-8327Dec 17, 2015
    risk 0.01cvss epss 0.10

    Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.

  • CVE-2015-3279Jul 14, 2015
    risk 0.01cvss epss 0.07

    Integer overflow in filter/texttopdf.c in texttopdf in cups-filters before 1.0.71 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted line size in a print job, which triggers a heap-based buffer overflow.

  • CVE-2015-3258Jul 14, 2015
    risk 0.01cvss epss 0.08

    Heap-based buffer overflow in the WriteProlog function in filter/texttopdf.c in texttopdf in cups-filters before 1.0.70 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a small line size in a print job.

  • CVE-2026-62290HigJul 16, 2026
    risk 0.00cvss 7.3epss 0.00

    cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing and using those certificates. From 1.18.0 until 1.19.6 and 1.20.3, Challenge resources under acme.cert-manager.io can be created…

  • CVE-2026-55175HigJul 10, 2026
    risk 0.00cvss 7.5epss 0.01

    Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco manifests. This can lead to remote code…

  • CVE-2026-24408NonJan 26, 2026
    risk 0.00cvss 0.0epss 0.00

    sigstore-python is a Python tool for generating and verifying Sigstore signatures. Prior to version 4.2.0, the sigstore-python OAuth authentication flow is susceptible to Cross-Site Request Forgery. `_OAuthSession` creates a unique "state" and sends it as a parameter in the…

  • CVE-2025-68132MedJan 21, 2026
    risk 0.00cvss 4.6epss 0.00

    EVerest is an EV charging software stack. Prior to version 2025.12.0, `is_message_crc_correct` in the DZG_GSH01 powermeter SLIP parser reads `vec[vec.size()-1]` and `vec[vec.size()-2]` without checking that at least two bytes are present. Malformed SLIP frames on the serial link…

  • CVE-2025-68133HigJan 21, 2026
    risk 0.00cvss 7.4epss 0.00

    EVerest is an EV charging software stack. In versions 2025.9.0 and below, an attacker can exhaust the operating system's memory and cause the module to terminate by initiating an unlimited number of TCP connections that never proceed to ISO 15118-2 communication. This is…

  • CVE-2025-69261HigDec 30, 2025
    risk 0.00cvss 7.5epss 0.00

    WasmEdge is a WebAssembly runtime. Prior to version 0.16.0-alpha.3, a multiplication in `WasmEdge/include/runtime/instance/memory.h` can wrap, causing `checkAccessBound()` to incorrectly allow the access. This leads to a segmentation fault. Version 0.16.0-alpha.3 contains a…

  • CVE-2025-51480HigJul 22, 2025
    risk 0.00cvss 8.8epss 0.01

    Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions.

  • CVE-2024-31584MedApr 19, 2024
    risk 0.00cvss 5.5epss 0.00

    Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp.

  • CVE-2023-39951MedAug 8, 2023
    risk 0.00cvss 6.5epss 0.01

    OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. OpenTelemetry Java Instrumentation prior to version 1.28.0 contains an issue related to the instrumentation of Java applications using the AWS SDK v2 with…

  • CVE-2023-24805HigMay 17, 2023
    risk 0.00cvss 8.8epss 0.04

    cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible network printer, this security vulnerability can cause remote…

  • CVE-2023-2250MedApr 24, 2023
    risk 0.00cvss 6.7epss 0.00

    A flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-manager-registration-controller or cluster-manager deployments. A malicious user can take advantage of this and bind the cluster-admin to any service account…

  • CVE-2021-4326LowMar 1, 2023
    risk 0.00cvss 3.3epss 0.00

    A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands via plugin install/update commands, or maliciously formed environment variables. Impacts Zowe CLI.

  • CVE-2021-32163CriFeb 17, 2023
    risk 0.00cvss 9.8epss 0.01

    Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.

  • CVE-2022-4875LowJan 4, 2023
    risk 0.00cvss 2.4epss 0.01

    A vulnerability has been found in fossology and classified as problematic. This vulnerability affects unknown code. The manipulation of the argument sql/VarValue leads to cross site scripting. The attack can be initiated remotely. The patch is identified as…

  • CVE-2022-23506MedJan 3, 2023
    risk 0.00cvss 4.3epss 0.01

    Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes, and Spinnaker's Rosco microservice produces machine images. Rosco prior to versions 1.29.2, 1.28.4, and 1.27.3 does not property mask secrets generated via packer builds. This…

  • CVE-2022-41939MedNov 19, 2022
    risk 0.00cvss 6.1epss 0.01

    knative.dev/func is is a client library and CLI enabling the development and deployment of Kubernetes functions. Developers using a malicious or compromised third-party buildpack could expose their registry credentials or local docker socket to a malicious `lifecycle` container.…

  • CVE-2022-34632CriJul 18, 2022
    risk 0.00cvss 9.1epss 0.01

    Rocket-Chip commit 4f8114374d8824dfdec03f576a8cd68bebce4e56 was discovered to contain insufficient cryptography via the component /rocket/RocketCore.scala.

  • CVE-2021-45701CriDec 27, 2021
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in the tremor-script crate before 0.11.6 for Rust. A patch operation may result in a use-after-free.

  • CVE-2021-41272HigDec 13, 2021
    risk 0.00cvss 7.5epss 0.01

    Besu is an Ethereum client written in Java. Starting in version 21.10.0, changes in the implementation of the SHL, SHR, and SAR operations resulted in the introduction of a signed type coercion error in values that represent negative values for 32 bit signed integers. Smart…

  • CVE-2021-43669HigNov 18, 2021
    risk 0.00cvss 7.5epss 0.01

    A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.0.1, v2.3.0. It can easily break down as many orderers as the attacker wants. This bug can be leveraged by constructing a message whose header is invalid to the interface Order. This bug has been admitted…

  • CVE-2021-43667HigNov 18, 2021
    risk 0.00cvss 7.5epss 0.01

    A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.1.0. This bug can be leveraged by constructing a message whose payload is nil and sending this message with the method 'forwardToLeader'. This bug has been admitted and fixed by the developers of Fabric.…

  • CVE-2021-31232MedApr 30, 2021
    risk 0.00cvss 5.5epss 0.00

    The Alertmanager in CNCF Cortex before 1.8.1 has a local file disclosure vulnerability when -experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a webhook. The alertmanager templates can be…

  • CVE-2021-20206HigMar 26, 2021
    risk 0.00cvss 7.2epss 0.02

    An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'type' field in the network configuration, it is possible to use special elements such as "../" separators to reference binaries…

  • CVE-2021-21369MedMar 9, 2021
    risk 0.00cvss 6.5epss 0.01

    Hyperledger Besu is an open-source, MainNet compatible, Ethereum client written in Java. In Besu before version 1.5.1 there is a denial-of-service vulnerability involving the HTTP JSON-RPC API service. If username and password authentication is enabled for the HTTP JSON-RPC API…

  • CVE-2020-28466HigMar 7, 2021
    risk 0.00cvss 7.5epss 0.04

    This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that represent a service export/import cycles. Disclaimer from the maintainers: Running a NATS service which is exposed to untrusted users…

  • CVE-2020-26273MedDec 16, 2020
    risk 0.00cvss 5.2epss 0.01

    osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. In osquery before version 4.6.0, by using sqlite's ATTACH verb, someone with administrative access to osquery can cause reads and writes to arbitrary sqlite databases on disk. This…

  • CVE-2020-11081MedJul 10, 2020
    risk 0.00cvss 5.3epss 0.01

    osquery before version 4.4.0 enables a privilege escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated…

  • CVE-2020-12831MedMay 13, 2020
    risk 0.00cvss 5.3epss 0.01

    An issue was discovered in FRRouting FRR (aka Free Range Routing) through 7.3.1. When using the split-config feature, the init script creates an empty config file with world-readable default permissions, leading to a possible information leak via tools/frr.in and…

  • CVE-2020-1887CriMar 13, 2020
    risk 0.00cvss 9.1epss 0.01

    Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker to MITM osquery traffic in the absence of a configured root chain of trust.

  • CVE-2015-2265Mar 24, 2015
    risk 0.00cvss epss 0.03

    The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vulnerability exists because of an incomplete fix for…

  • CVE-2014-4338Jun 22, 2014
    risk 0.00cvss epss 0.03

    cups-browsed in cups-filters before 1.0.53 allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging a malformed cups-browsed.conf BrowseAllow directive that is interpreted as granting browse access to all IP addresses.

  • CVE-2014-4337Jun 22, 2014
    risk 0.00cvss epss 0.03

    The process_browse_data function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted packet data.

Page 11 of 12