Количество 40
Количество 40

RLSA-2020:4694
Moderate: container-tools:rhel8 security, bug fix, and enhancement update
ELSA-2020-4694
ELSA-2020-4694: container-tools:ol8 security, bug fix, and enhancement update (MODERATE)

CVE-2020-10749
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

CVE-2020-10749
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

CVE-2020-10749
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.
CVE-2020-10749
A vulnerability was found in all versions of containernetworking/plugi ...

openSUSE-SU-2020:1050-1
Security update for cni-plugins

openSUSE-SU-2020:1049-1
Security update for cni-plugins

SUSE-SU-2020:1957-1
Security update for cni-plugins
GHSA-fx6x-h9g4-56f8
containernetworking/plugins vulnerable to MitM attacks
ELSA-2020-2684
ELSA-2020-2684: containernetworking-plugins security update (MODERATE)

SUSE-SU-2022:4151-1
Security update for cni-plugins
ELSA-2020-5727
ELSA-2020-5727: kubernetes-cni-plugins kubernetes-cni kubernetes olcne security update (IMPORTANT)
ELSA-2020-5725
ELSA-2020-5725: kubernetes kubeadm-ha-setup kubernetes-cni kubernetes-cni-plugins security update (IMPORTANT)

CVE-2020-14040
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.

CVE-2020-14040
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.

CVE-2020-14040
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String.
CVE-2020-14040
The x/text package before 0.3.3 for Go has a vulnerability in encoding ...
ELSA-2020-5726
ELSA-2020-5726: grafana kubernetes-cni kubernetes-cni-plugins kubernetes kubernetes olcne security update (IMPORTANT)

CVE-2020-10756
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | RLSA-2020:4694 Moderate: container-tools:rhel8 security, bug fix, and enhancement update | больше 4 лет назад | ||
ELSA-2020-4694 ELSA-2020-4694: container-tools:ol8 security, bug fix, and enhancement update (MODERATE) | больше 4 лет назад | |||
![]() | CVE-2020-10749 A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container. | CVSS3: 6 | 4% Низкий | около 5 лет назад |
![]() | CVE-2020-10749 A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container. | CVSS3: 6 | 4% Низкий | около 5 лет назад |
![]() | CVE-2020-10749 A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container. | CVSS3: 6 | 4% Низкий | около 5 лет назад |
CVE-2020-10749 A vulnerability was found in all versions of containernetworking/plugi ... | CVSS3: 6 | 4% Низкий | около 5 лет назад | |
![]() | openSUSE-SU-2020:1050-1 Security update for cni-plugins | 4% Низкий | почти 5 лет назад | |
![]() | openSUSE-SU-2020:1049-1 Security update for cni-plugins | 4% Низкий | почти 5 лет назад | |
![]() | SUSE-SU-2020:1957-1 Security update for cni-plugins | 4% Низкий | почти 5 лет назад | |
GHSA-fx6x-h9g4-56f8 containernetworking/plugins vulnerable to MitM attacks | CVSS3: 6 | 4% Низкий | около 3 лет назад | |
ELSA-2020-2684 ELSA-2020-2684: containernetworking-plugins security update (MODERATE) | почти 5 лет назад | |||
![]() | SUSE-SU-2022:4151-1 Security update for cni-plugins | больше 2 лет назад | ||
ELSA-2020-5727 ELSA-2020-5727: kubernetes-cni-plugins kubernetes-cni kubernetes olcne security update (IMPORTANT) | около 5 лет назад | |||
ELSA-2020-5725 ELSA-2020-5725: kubernetes kubeadm-ha-setup kubernetes-cni kubernetes-cni-plugins security update (IMPORTANT) | около 5 лет назад | |||
![]() | CVE-2020-14040 The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String. | CVSS3: 7.5 | 0% Низкий | около 5 лет назад |
![]() | CVE-2020-14040 The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String. | CVSS3: 7.5 | 0% Низкий | около 5 лет назад |
![]() | CVE-2020-14040 The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Decoder is called, or the Decoder is passed to golang.org/x/text/transform.String. | CVSS3: 7.5 | 0% Низкий | около 5 лет назад |
CVE-2020-14040 The x/text package before 0.3.3 for Go has a vulnerability in encoding ... | CVSS3: 7.5 | 0% Низкий | около 5 лет назад | |
ELSA-2020-5726 ELSA-2020-5726: grafana kubernetes-cni kubernetes-cni-plugins kubernetes kubernetes olcne security update (IMPORTANT) | около 5 лет назад | |||
![]() | CVE-2020-10756 An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1. | CVSS3: 6.5 | 0% Низкий | почти 5 лет назад |
Уязвимостей на страницу