Логотип exploitDog
bind:"CVE-2020-10749" OR bind:"CVE-2020-10756" OR bind:"CVE-2020-14040"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2020-10749" OR bind:"CVE-2020-10756" OR bind:"CVE-2020-14040"

Количество 40

Количество 40

rocky логотип

RLSA-2020:4694

больше 4 лет назад

Moderate: container-tools:rhel8 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2020-4694

больше 4 лет назад

ELSA-2020-4694: container-tools:ol8 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2020-10749

около 5 лет назад

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

CVSS3: 6
EPSS: Низкий
redhat логотип

CVE-2020-10749

около 5 лет назад

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

CVSS3: 6
EPSS: Низкий
nvd логотип

CVE-2020-10749

около 5 лет назад

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

CVSS3: 6
EPSS: Низкий
debian логотип

CVE-2020-10749

около 5 лет назад

A vulnerability was found in all versions of containernetworking/plugi ...

CVSS3: 6
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:1050-1

почти 5 лет назад

Security update for cni-plugins

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:1049-1

почти 5 лет назад

Security update for cni-plugins

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1957-1

почти 5 лет назад

Security update for cni-plugins

EPSS: Низкий
github логотип

GHSA-fx6x-h9g4-56f8

около 3 лет назад

containernetworking/plugins vulnerable to MitM attacks

CVSS3: 6
EPSS: Низкий
oracle-oval логотип

ELSA-2020-2684

почти 5 лет назад

ELSA-2020-2684: containernetworking-plugins security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4151-1

больше 2 лет назад

Security update for cni-plugins

EPSS: Низкий
oracle-oval логотип

ELSA-2020-5727

около 5 лет назад

ELSA-2020-5727: kubernetes-cni-plugins kubernetes-cni kubernetes olcne security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-5725

около 5 лет назад

ELSA-2020-5725: kubernetes kubeadm-ha-setup kubernetes-cni kubernetes-cni-plugins security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2020-14040

около 5 лет назад

The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2020-14040

около 5 лет назад

The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2020-14040

около 5 лет назад

The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2020-14040

около 5 лет назад

The x/text package before 0.3.3 for Go has a vulnerability in encoding ...

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2020-5726

около 5 лет назад

ELSA-2020-5726: grafana kubernetes-cni kubernetes-cni-plugins kubernetes kubernetes olcne security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2020-10756

почти 5 лет назад

An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2020:4694

Moderate: container-tools:rhel8 security, bug fix, and enhancement update

больше 4 лет назад
oracle-oval логотип
ELSA-2020-4694

ELSA-2020-4694: container-tools:ol8 security, bug fix, and enhancement update (MODERATE)

больше 4 лет назад
ubuntu логотип
CVE-2020-10749

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

CVSS3: 6
4%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-10749

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

CVSS3: 6
4%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-10749

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

CVSS3: 6
4%
Низкий
около 5 лет назад
debian логотип
CVE-2020-10749

A vulnerability was found in all versions of containernetworking/plugi ...

CVSS3: 6
4%
Низкий
около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:1050-1

Security update for cni-plugins

4%
Низкий
почти 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:1049-1

Security update for cni-plugins

4%
Низкий
почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:1957-1

Security update for cni-plugins

4%
Низкий
почти 5 лет назад
github логотип
GHSA-fx6x-h9g4-56f8

containernetworking/plugins vulnerable to MitM attacks

CVSS3: 6
4%
Низкий
около 3 лет назад
oracle-oval логотип
ELSA-2020-2684

ELSA-2020-2684: containernetworking-plugins security update (MODERATE)

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2022:4151-1

Security update for cni-plugins

больше 2 лет назад
oracle-oval логотип
ELSA-2020-5727

ELSA-2020-5727: kubernetes-cni-plugins kubernetes-cni kubernetes olcne security update (IMPORTANT)

около 5 лет назад
oracle-oval логотип
ELSA-2020-5725

ELSA-2020-5725: kubernetes kubeadm-ha-setup kubernetes-cni kubernetes-cni-plugins security update (IMPORTANT)

около 5 лет назад
ubuntu логотип
CVE-2020-14040

The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.

CVSS3: 7.5
0%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-14040

The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.

CVSS3: 7.5
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-14040

The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.

CVSS3: 7.5
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-14040

The x/text package before 0.3.3 for Go has a vulnerability in encoding ...

CVSS3: 7.5
0%
Низкий
около 5 лет назад
oracle-oval логотип
ELSA-2020-5726

ELSA-2020-5726: grafana kubernetes-cni kubernetes-cni-plugins kubernetes kubernetes olcne security update (IMPORTANT)

около 5 лет назад
ubuntu логотип
CVE-2020-10756

An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.

CVSS3: 6.5
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу