Openeuler
Products
16- 6 CVEs
- 5 CVEs
- 4 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 0 CVEs
Recent CVEs
23| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-33635 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2023 | When malicious images are pulled by isula pull, attackers can execute arbitrary code. | ||
| CVE-2021-33638 | Hig | 0.55 | 8.4 | 0.00 | Oct 29, 2023 | When the isula cp command is used to copy files from a container to a host machine and the container is controlled by an attacker, the attacker can escape the container. | ||
| CVE-2021-33637 | Hig | 0.55 | 8.4 | 0.00 | Oct 29, 2023 | When the isula export command is used to export a container to an image and the container is controlled by an attacker, the attacker can escape the container. | ||
| CVE-2021-33636 | Hig | 0.55 | 8.4 | 0.00 | Oct 29, 2023 | When the isula load command is used to load malicious images, attackers can execute arbitrary code. | ||
| CVE-2024-24897 | Hig | 0.53 | 8.1 | 0.01 | Mar 25, 2024 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in openEuler A-Tune-Collector on Linux allows Command Injection. This vulnerability is associated with program files https://gitee.Com/openeuler/A-Tune-Collector/blob/master/atune_co… | ||
| CVE-2024-24892 | Hig | 0.53 | 8.1 | 0.01 | Mar 25, 2024 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Privilege Management vulnerability in openEuler migration-tools on Linux allows Command Injection, Restful Privilege Elevation. This vulnerability is associated with program… | ||
| CVE-2024-24890 | Hig | 0.51 | 7.8 | 0.01 | Mar 25, 2024 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler gala-gopher on Linux allows Command Injection. This vulnerability is associated with program files https://gitee.Com/openeuler/gala-gopher/blob/master/src/probes/… | ||
| CVE-2021-33641 | Hig | 0.51 | 7.8 | 0.00 | Jan 20, 2023 | When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses the released memory (use after free). | ||
| CVE-2021-33658 | Hig | 0.51 | 7.8 | 0.00 | Mar 11, 2022 | atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate the local privilege or modify any file. Authentication is not forcibly enabled in the default configuration. | ||
| CVE-2021-33639 | Hig | 0.49 | 7.5 | 0.00 | Mar 8, 2023 | REMAP cmd of SVM driver can be used to remap read only memory as read-write, then cause read only memory/file modified. | ||
| CVE-2021-33629 | Hig | 0.49 | 7.5 | 0.01 | Jul 26, 2021 | isula-build before 0.9.5-6 can cause a program crash, when building container images, some functions for processing external data do not remove spaces when processing data. | ||
| CVE-2021-33633 | Hig | 0.48 | 7.3 | 0.01 | Mar 23, 2024 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-ceres on Linux allows Command Injection. This vulnerability is associated with program files ceres/function/util.Py. This issue affects aops-ceres: from… | ||
| CVE-2025-31344 | Hig | 0.47 | 7.3 | 0.00 | Apr 14, 2025 | Heap-based Buffer Overflow vulnerability in openEuler giflib on Linux. This vulnerability is associated with program files gif2rgb.C. This issue affects giflib: through 5.2.2. | ||
| CVE-2024-24899 | Hig | 0.47 | 7.2 | 0.02 | Mar 25, 2024 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-zeus on Linux allows Command Injection. This vulnerability is associated with program files https://gitee.Com/openeuler/aops-zeus/blob/master/zeus/conf/const… | ||
| CVE-2021-33632 | Hig | 0.46 | 7.0 | 0.00 | Mar 25, 2024 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in openEuler iSulad on Linux allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This vulnerability is associated with program files https://gitee.Com/openeuler/iSulad/blob/master/src/cmd/isulad… | ||
| CVE-2021-33656 | Med | 0.44 | 6.8 | 0.01 | Jul 18, 2022 | When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds. | ||
| CVE-2021-33634 | Med | 0.41 | 6.3 | 0.00 | Oct 29, 2023 | iSulad uses the lcr+lxc runtime (default) to run malicious images, which can cause DOS. | ||
| CVE-2021-33640 | Med | 0.40 | 6.2 | 0.01 | Dec 19, 2022 | After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free). | ||
| CVE-2024-24898 | Med | 0.39 | 6.0 | 0.00 | Apr 15, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerability is associated with program files https://gitee.Com/openeuler/kernel/blob/openEuler-1.0-LTS/drivers/staging/gmjstcm/tcm.C. This… | ||
| CVE-2024-24891 | Med | 0.39 | 6.0 | 0.00 | Apr 15, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerability is associated with program files https://gitee.Com/openeuler/kernel/blob/openEuler-1.0-LTS/drivers/staging/gmjstcm/tcm.C. This… |
- risk 0.64cvss 9.8epss 0.01
When malicious images are pulled by isula pull, attackers can execute arbitrary code.
- risk 0.55cvss 8.4epss 0.00
When the isula cp command is used to copy files from a container to a host machine and the container is controlled by an attacker, the attacker can escape the container.
- risk 0.55cvss 8.4epss 0.00
When the isula export command is used to export a container to an image and the container is controlled by an attacker, the attacker can escape the container.
- risk 0.55cvss 8.4epss 0.00
When the isula load command is used to load malicious images, attackers can execute arbitrary code.
- risk 0.53cvss 8.1epss 0.01
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in openEuler A-Tune-Collector on Linux allows Command Injection. This vulnerability is associated with program files https://gitee.Com/openeuler/A-Tune-Collector/blob/master/atune_co…
- risk 0.53cvss 8.1epss 0.01
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Privilege Management vulnerability in openEuler migration-tools on Linux allows Command Injection, Restful Privilege Elevation. This vulnerability is associated with program…
- risk 0.51cvss 7.8epss 0.01
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler gala-gopher on Linux allows Command Injection. This vulnerability is associated with program files https://gitee.Com/openeuler/gala-gopher/blob/master/src/probes/…
- risk 0.51cvss 7.8epss 0.00
When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses the released memory (use after free).
- risk 0.51cvss 7.8epss 0.00
atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate the local privilege or modify any file. Authentication is not forcibly enabled in the default configuration.
- risk 0.49cvss 7.5epss 0.00
REMAP cmd of SVM driver can be used to remap read only memory as read-write, then cause read only memory/file modified.
- risk 0.49cvss 7.5epss 0.01
isula-build before 0.9.5-6 can cause a program crash, when building container images, some functions for processing external data do not remove spaces when processing data.
- risk 0.48cvss 7.3epss 0.01
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-ceres on Linux allows Command Injection. This vulnerability is associated with program files ceres/function/util.Py. This issue affects aops-ceres: from…
- risk 0.47cvss 7.3epss 0.00
Heap-based Buffer Overflow vulnerability in openEuler giflib on Linux. This vulnerability is associated with program files gif2rgb.C. This issue affects giflib: through 5.2.2.
- risk 0.47cvss 7.2epss 0.02
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-zeus on Linux allows Command Injection. This vulnerability is associated with program files https://gitee.Com/openeuler/aops-zeus/blob/master/zeus/conf/const…
- risk 0.46cvss 7.0epss 0.00
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in openEuler iSulad on Linux allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This vulnerability is associated with program files https://gitee.Com/openeuler/iSulad/blob/master/src/cmd/isulad…
- risk 0.44cvss 6.8epss 0.01
When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds.
- risk 0.41cvss 6.3epss 0.00
iSulad uses the lcr+lxc runtime (default) to run malicious images, which can cause DOS.
- risk 0.40cvss 6.2epss 0.01
After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free).
- risk 0.39cvss 6.0epss 0.00
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerability is associated with program files https://gitee.Com/openeuler/kernel/blob/openEuler-1.0-LTS/drivers/staging/gmjstcm/tcm.C. This…
- risk 0.39cvss 6.0epss 0.00
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerability is associated with program files https://gitee.Com/openeuler/kernel/blob/openEuler-1.0-LTS/drivers/staging/gmjstcm/tcm.C. This…