VYPR

Vendor CVEs

Linux Foundation

All CVEs

558 total · sorted by risk
  • CVE-2025-55552HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.

  • CVE-2025-55551HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.

  • CVE-2025-59353HigSep 17, 2025
    risk 0.49cvss 7.5epss 0.00

    Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for arbitrary IP addresses, effectively rendering the mTLS authentication useless. The issue is that the Manager’s Certificate gRPC…

  • CVE-2025-59348HigSep 17, 2025
    risk 0.49cvss 7.5epss 0.00

    Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the processPieceFromSource method does not update the structure’s usedTraffic field, because an uninitialized variable n is used as a guard to the AddTraffic method call,…

  • CVE-2025-47291HigMay 21, 2025
    risk 0.49cvss 7.5epss 0.00

    containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 and prior to version 2.0.5, doesn't put usernamespaced containers under the Kubernetes' cgroup hierarchy, therefore some Kubernetes…

  • CVE-2024-24423HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.01

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_esm_message_container function at /nas/ies/EsmMessageContainer.cpp. This vulnerability allows attackers to cause a Denial…

  • CVE-2024-24422HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.01

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a stack overflow in the decode_protocol_configuration_options function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows attackers to cause a…

  • CVE-2024-24420HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.01

    A reachable assertion in the decode_linked_ti_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

  • CVE-2024-24419HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.01

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_traffic_flow_template_packet_filter function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows attackers to cause…

  • CVE-2024-24418HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.01

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_pdn_address function at /nas/ies/PdnAddress.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS)…

  • CVE-2024-24417HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.01

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_protocol_configuration_options function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows attackers to cause a…

  • CVE-2024-24416HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.01

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_access_point_name_ie function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows attackers to cause a Denial of…

  • CVE-2023-37032HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.01

    A Stack-based buffer overflow in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cellphone by sending a NAS packet containing an…

  • CVE-2023-37029HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.01

    Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) are susceptible to an assertion-based crash when an oversized NAS packet is received. An attacker may leverage this behavior to repeatedly crash the MME via either a compromised base station…

  • CVE-2023-37024HigJan 21, 2025
    risk 0.49cvss 7.5epss 0.01

    A reachable assertion in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cellphone by sending a NAS packet containing an `Emergency…

  • CVE-2024-20153HigJan 6, 2025
    risk 0.49cvss 7.5epss 0.00

    In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442;…

  • CVE-2024-20089HigSep 2, 2024
    risk 0.49cvss 7.5epss 0.00

    In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08861558; Issue ID: MSV-1526.

  • CVE-2023-32820HigOct 2, 2023
    risk 0.49cvss 7.5epss 0.00

    In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue ID: ALPS07932637.

  • CVE-2023-20693HigJul 4, 2023
    risk 0.49cvss 7.5epss 0.00

    In wlan firmware, there is possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664711; Issue ID: ALPS07664711.

  • CVE-2023-20692HigJul 4, 2023
    risk 0.49cvss 7.5epss 0.00

    In wlan firmware, there is possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664720; Issue ID: ALPS07664720.

  • CVE-2023-20691HigJul 4, 2023
    risk 0.49cvss 7.5epss 0.00

    In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664731; Issue ID: ALPS07664731.

  • CVE-2023-20690HigJul 4, 2023
    risk 0.49cvss 7.5epss 0.00

    In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664735; Issue ID: ALPS07664735.

  • CVE-2023-20689HigJul 4, 2023
    risk 0.49cvss 7.5epss 0.00

    In wlan firmware, there is possible system crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07664741; Issue ID: ALPS07664741.

  • CVE-2022-32666HigJul 4, 2023
    risk 0.49cvss 7.5epss 0.01

    In Wi-Fi, there is a possible low throughput due to misrepresentation of critical information. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220829014; Issue ID:…

  • CVE-2023-25151HigFeb 8, 2023
    risk 0.49cvss 7.5epss 0.01

    opentelemetry-go-contrib is a collection of extensions for OpenTelemetry-Go. The v0.38.0 release of `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` uses the `httpconv.ServerRequest` function to annotate metric measurements for the…

  • CVE-2022-46463HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.06

    An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."

  • CVE-2022-45932HigNov 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/RoleStore.java deleteRole function is affected when the API interface /auth/v1/roles/ is used.

  • CVE-2022-45931HigNov 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/UserStore.java deleteUser function is affected when the API interface /auth/v1/users/ is used.

  • CVE-2022-45930HigNov 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/DomainStore.java deleteDomain function is affected for the /auth/v1/domains/ API interface.

  • CVE-2022-32589HigOct 7, 2022
    risk 0.49cvss 7.5epss 0.01

    In Wi-Fi driver, there is a possible way to disconnect Wi-Fi due to an improper resource release. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07030600; Issue ID:…

  • CVE-2022-38817HigOct 3, 2022
    risk 0.49cvss 7.5epss 0.03

    Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data.

  • CVE-2021-36155HigJul 9, 2021
    risk 0.49cvss 7.5epss 0.02

    LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote attackers to cause uncontrolled resource consumption and deny service.

  • CVE-2021-36154HigJul 9, 2021
    risk 0.49cvss 7.5epss 0.02

    HTTP2ToRawGRPCServerCodec in gRPC Swift 1.1.1 and earlier allows remote attackers to deny service via the delivery of many small messages within a single HTTP/2 frame, leading to Uncontrolled Recursion and stack consumption.

  • CVE-2021-36153HigJul 9, 2021
    risk 0.49cvss 7.5epss 0.02

    Mismanaged state in GRPCWebToHTTP2ServerCodec.swift in gRPC Swift 1.1.0 and 1.1.1 allows remote attackers to deny service by sending malformed requests.

  • CVE-2021-30465HigMay 27, 2021
    risk 0.49cvss 8.5epss 0.07

    runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on…

  • CVE-2020-15687HigAug 31, 2020
    risk 0.49cvss 7.5epss 0.02

    Missing access control restrictions in the Hypervisor component of the ACRN Project (v2.0 and v1.6.1) allow a malicious entity, with root access in the Service VM userspace, to abuse the PCIe assign/de-assign Hypercalls via crafted ioctls and payloads. This attack results in a…

  • CVE-2020-11090HigJun 11, 2020
    risk 0.49cvss 7.5epss 0.02

    In Indy Node 1.12.2, there is an Uncontrolled Resource Consumption vulnerability. Indy Node has a bug in TAA handling code. The current primary can be crashed with a malformed transaction from a client, which leads to a view change. Repeated rapid view changes have the potential…

  • CVE-2020-12059HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception.

  • CVE-2020-1699HigApr 21, 2020
    risk 0.49cvss 7.5epss 0.02

    A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use this flaw to cause information disclosure on the host machine…

  • CVE-2019-16302HigFeb 20, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Open Network Operating System (ONOS) 1.14. In the Ethernet VPN application (org.onosproject.evpnopenflow), the host event listener does not handle the following event types: HOST_MOVED, HOST_UPDATED. In combination with other applications, this could…

  • CVE-2019-16301HigFeb 20, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Open Network Operating System (ONOS) 1.14. In the virtual tenant network application (org.onosproject.vtn), the host event listener does not handle the following event types: HOST_MOVED. In combination with other applications, this could lead to the…

  • CVE-2019-16300HigFeb 20, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Open Network Operating System (ONOS) 1.14. In the access control application (org.onosproject.acl), the host event listener does not handle the following event types: HOST_REMOVED. In combination with other applications, this could lead to the absence…

  • CVE-2019-16299HigFeb 20, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Open Network Operating System (ONOS) 1.14. In the mobility application (org.onosproject.mobility), the host event listener does not handle the following event types: HOST_ADDED, HOST_REMOVED, HOST_UPDATED. In combination with other applications, this…

  • CVE-2019-16298HigFeb 20, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Open Network Operating System (ONOS) 1.14. In the virtual broadband network gateway application (org.onosproject.virtualbng), the host event listener does not handle the following event types: HOST_MOVED, HOST_REMOVED, HOST_UPDATED. In combination with…

  • CVE-2019-16297HigFeb 20, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Open Network Operating System (ONOS) 1.14. In the P4 tutorial application (org.onosproject.p4tutorial), the host event listener does not handle the following event types: HOST_MOVED, HOST_REMOVED, HOST_UPDATED. In combination with other applications,…

  • CVE-2018-20730HigJan 17, 2019
    risk 0.49cvss 7.5epss 0.01

    A SQL injection vulnerability in NeDi before 1.7Cp3 allows any user to execute arbitrary SQL read commands via the query.php component.

  • CVE-2026-23995HigMar 26, 2026
    risk 0.48cvss 8.4epss 0.00

    EVerest is an EV charging software stack. Prior to version 2026.02.0, stack-based buffer overflow in CAN interface initialization: passing an interface name longer than IFNAMSIZ (16) to CAN open routines overflows `ifreq.ifr_name`, corrupting adjacent stack data and enabling…

  • CVE-2026-22593HigMar 26, 2026
    risk 0.48cvss 8.4epss 0.00

    EVerest is an EV charging software stack. Prior to version 2026.02.0, an off-by-one check in IsoMux certificate filename handling causes a stack-based buffer overflow when a filename length equals `MAX_FILE_NAME_LENGTH` (100). A crafted filename in the certificate directory can…

  • CVE-2025-68141HigJan 21, 2026
    risk 0.48cvss 7.4epss 0.00

    EVerest is an EV charging software stack. Prior to version 2025.10.0, during the deserialization of a `DC_ChargeLoopRes` message that includes Receipt as well as TaxCosts, the vector `tax_costs` in the target `Receipt` structure is accessed out of bounds. This…

  • CVE-2025-68136HigJan 21, 2026
    risk 0.48cvss 7.4epss 0.00

    EVerest is an EV charging software stack. Prior to version 2025.10.0, once the module receives a SDP request, it creates a whole new set of objects like `Session`, `IConnection` which open new TCP socket for the ISO15118-20 communications and registers callbacks for the created…

Page 3 of 12