Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2022-38060High· 7.8OpenStack Kolla sudo privilege escalation vulnerability
OpenStack Kolla sudo privilege escalation vulnerability
CVE-2022-44940Critical· 9.1Patchelf out-of-bounds read
Patchelf out-of-bounds read
CVE-2022-4589Medium· 6.1Terms and Conditions Module vulnerable to Open Redirect
Terms and Conditions Module vulnerable to Open Redirect
CVE-2022-23524High· 7.5⚖ disputedhelm: Denial of service through string value parsing (CVE-2022-23524)
A flaw was found in Helm, a tool for managing Charts, a pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption. Input to functions in the _strvals_ package could cause a stack overflo…
CVE-2022-23526High· 7.5⚖ disputedhelm: Denial of service through schema file (CVE-2022-23526)
A flaw was found in Helm, a tool for managing Charts, a pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the_chartutil_ package that could cause a segmentation violation. The _chartut…
CVE-2022-23525High· 7.5⚖ disputedhelm: Denial of service through through repository index file (CVE-2022-23525)
A flaw was found in Helm. Applications that use the _repo_ package in Helm SDK to parse an index file may suffer a denial of service when that input causes a panic that cannot be recovered from. The Helm Client will panic with an index fil…
CVE-2022-4223High· 8.8PoCpgadmin4 vulnerable to Code Injection
pgadmin4 vulnerable to Code Injection
CVE-2022-4396Medium· 5.4pyRdfa3 Cross-site Scripting vulnerability
pyRdfa3 Cross-site Scripting vulnerability
CVE-2022-23469Low· 3.5Traefik may display authorization header in the debug logs
Traefik may display authorization header in the debug logs
CVE-2022-46153Medium· 6.5Traefik routes exposed with an empty TLSOption
Traefik routes exposed with an empty TLSOption
CVE-2022-23471Medium· 5.7containerd CRI stream server vulnerable to host memory exhaustion via terminal
containerd CRI stream server vulnerable to host memory exhaustion via terminal
CVE-2022-46742Critical· 9.8PaddlePaddle vulnerable to Code Injection
PaddlePaddle vulnerable to Code Injection
CVE-2022-46741Critical· 9.1PaddlePaddle Out-of-bounds Read vulnerability
PaddlePaddle Out-of-bounds Read vulnerability
CVE-2022-46146Medium· 6.2Prometheus Exporter-Toolkit is vulnerable to authentication bypass
Prometheus Exporter-Toolkit is vulnerable to authentication bypass
CVE-2022-45908Critical· 9.8PaddlePaddle vulnerable to code injection via winstr
PaddlePaddle vulnerable to code injection via winstr
CVE-2022-41131High· 7.8OS Command Injection in Apache Airflow
OS Command Injection in Apache Airflow
CVE-2022-41880Medium· 6.8Tensorflow vulnerable to Out-of-Bounds Read
Tensorflow vulnerable to Out-of-Bounds Read
CVE-2022-40954Medium· 5.5OS Command Injection in Apache Airflow
OS Command Injection in Apache Airflow
CVE-2022-41889Medium· 5.5Segfault via invalid attributes in `pywrap_tfe_src.cc`
Segfault via invalid attributes in `pywrap_tfe_src.cc`
CVE-2022-41900High· 7.1FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess
FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess
CVE-2022-41883Medium· 6.8Out of bounds segmentation fault due to unequal op inputs in Tensorflow
Out of bounds segmentation fault due to unequal op inputs in Tensorflow
CVE-2022-41896Medium· 4.8`tf.raw_ops.Mfcc` crashes
`tf.raw_ops.Mfcc` crashes
CVE-2022-41909Medium· 4.8Segfault in `CompositeTensorVariantToComponents`
Segfault in `CompositeTensorVariantToComponents`
CVE-2022-41911Medium· 4.8Invalid char to bool conversion when printing a tensor
Invalid char to bool conversion when printing a tensor
CVE-2022-41908Medium· 4.8`CHECK` fail via inputs in `PyFunc`
`CHECK` fail via inputs in `PyFunc`
CVE-2022-41884Medium· 4.8Seg fault in `ndarray_tensor_bridge` due to zero and large inputs
Seg fault in `ndarray_tensor_bridge` due to zero and large inputs
CVE-2022-41898Medium· 4.8`CHECK` fail via inputs in `SparseFillEmptyRowsGrad`
`CHECK` fail via inputs in `SparseFillEmptyRowsGrad`
CVE-2022-4105Medium· 5.4Cross-site Scripting in kiwitcms
Cross-site Scripting in kiwitcms
CVE-2022-41894High· 7.1Buffer overflow in `CONV_3D_TRANSPOSE` on TFLite
Buffer overflow in `CONV_3D_TRANSPOSE` on TFLite
CVE-2022-41890Medium· 4.8`CHECK` fail in `BCast` overflow
`CHECK` fail in `BCast` overflow