Search Results (356 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-31022 8 Canonical, Citrix, Linux and 5 more 9 Ubuntu Linux, Hypervisor, Linux Kernel and 6 more 2025-02-27 5.5 Medium
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a NULL-pointer dereference may lead to denial of service.
CVE-2023-23939 1 Microsoft 1 Azure Setup Kubectl 2025-02-25 3.9 Low
Azure/setup-kubectl is a GitHub Action for installing Kubectl. This vulnerability only impacts versions before version 3. An insecure temporary creation of a file allows other actors on the Actions runner to replace the Kubectl binary created by this action because it is world writable. This Kubectl tool installer runs `fs.chmodSync(kubectlPath, 777)` to set permissions on the Kubectl binary, however, this allows any local user to replace the Kubectl binary. This allows privilege escalation to the user that can also run kubectl, most likely root. This attack is only possible if an attacker somehow breached the GitHub actions runner or if a user is utilizing an Action that maliciously executes this attack. This has been fixed and released in all versions `v3` and later. 775 permissions are used instead. Users are advised to upgrade. There are no known workarounds for this issue.
CVE-2024-27099 1 Microsoft 1 Azure Uamqp 2025-02-14 9.8 Critical
The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect `AMQP_VALUE` failed state, may cause a double free problem. This may cause a RCE. Update submodule with commit 2ca42b6e4e098af2d17e487814a91d05f6ae4987.
CVE-2022-35784 1 Microsoft 1 Azure Site Recovery Vmware To Azure 2025-02-12 6.5 Medium
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35783 1 Microsoft 1 Azure Site Recovery Vmware To Azure 2025-02-12 4.4 Medium
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2023-24513 5 Amazon, Arista, Equinix and 2 more 6 Aws Marketplace, Cloudeos, Dca-200-veos and 3 more 2025-02-07 6.5 Medium
On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding traffic.
CVE-2023-28312 1 Microsoft 1 Azure Machine Learning 2025-01-23 6.5 Medium
Azure Machine Learning Information Disclosure Vulnerability
CVE-2023-28300 1 Microsoft 1 Azure Service Connector 2025-01-23 7.5 High
Azure Service Connector Security Feature Bypass Vulnerability
CVE-2022-37968 1 Microsoft 2 Azure Arc-enabled Kubernetes, Azure Stack Edge 2025-01-02 10 Critical
Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over the Kubernetes cluster. Additionally, because Azure Stack Edge allows customers to deploy Kubernetes workloads on their devices via Azure Arc, Azure Stack Edge devices are also vulnerable to this vulnerability.
CVE-2022-35829 1 Microsoft 1 Azure Service Fabric 2025-01-02 6.2 Medium
Service Fabric Explorer Spoofing Vulnerability
CVE-2022-41051 1 Microsoft 1 Azure Rtos Guix Studio 2025-01-02 7.8 High
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
CVE-2022-41085 1 Microsoft 1 Azure Cyclecloud 2025-01-02 7.5 High
Azure CycleCloud Elevation of Privilege Vulnerability
CVE-2022-38014 1 Microsoft 2 Azure Iot Edge For Linux, Windows Subsystem For Linux 2025-01-02 7 High
Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability
CVE-2022-35824 1 Microsoft 1 Azure Site Recovery 2025-01-02 7.2 High
Azure Site Recovery Remote Code Execution Vulnerability
CVE-2022-35821 1 Microsoft 1 Azure Sphere 2025-01-02 4.4 Medium
Azure Sphere Information Disclosure Vulnerability
CVE-2022-35819 1 Microsoft 1 Azure Site Recovery 2025-01-02 6.5 Medium
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35818 1 Microsoft 1 Azure Site Recovery 2025-01-02 6.5 Medium
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35791 1 Microsoft 1 Azure Site Recovery Vmware To Azure 2025-01-02 6.5 Medium
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35817 1 Microsoft 1 Azure Site Recovery 2025-01-02 6.5 Medium
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35816 1 Microsoft 1 Azure Site Recovery 2025-01-02 6.5 Medium
Azure Site Recovery Elevation of Privilege Vulnerability