Логотип exploitDog
bind:"CVE-2019-10214" OR bind:"CVE-2019-14378" OR bind:"CVE-2019-9946"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2019-10214" OR bind:"CVE-2019-14378" OR bind:"CVE-2019-9946"

Количество 55

Количество 55

nvd логотип

CVE-2019-9946

около 6 лет назад

Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-9946

около 6 лет назад

Cloud Native Computing Foundation (CNCF) CNI (Container Networking Int ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0310-1

больше 4 лет назад

Security update for buildah, libcontainers-common, podman

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:2106-1

больше 4 лет назад

Security update for buildah

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:3423-1

больше 4 лет назад

Security update for buildah

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:0770-1

больше 3 лет назад

Security update for buildah

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:0770-1

больше 3 лет назад

Security update for buildah

EPSS: Низкий
ubuntu логотип

CVE-2019-14378

почти 6 лет назад

ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2019-14378

почти 6 лет назад

ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2019-14378

почти 6 лет назад

ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-14378

почти 6 лет назад

ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overf ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-6g96-g4m6-hw69

около 3 лет назад

Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:0554-1

около 5 лет назад

Security update for kubernetes

EPSS: Низкий
oracle-oval логотип

ELSA-2019-4593

около 6 лет назад

ELSA-2019-4593: kubernetes kubeadm-upgrade kubeadm-ha-setup security update (IMPORTANT)

EPSS: Низкий
github логотип

GHSA-qvqc-h5c8-h785

около 3 лет назад

ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.

EPSS: Низкий
fstec логотип

BDU:2019-03648

почти 6 лет назад

Уязвимость функции ip_reass из ip_input.c библиотеки TCP-IP эмулятора Libslirp, позволяющая нарушителю получить несанкционированный доступ к информации, вызвать отказ в обслуживании или оказать воздействие на доступность информации

CVSS3: 8.8
EPSS: Низкий
oracle-oval логотип

ELSA-2020-0366

больше 5 лет назад

ELSA-2020-0366: qemu-kvm security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2059-1

почти 6 лет назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2353-1

почти 6 лет назад

Security update for qemu

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2246-1

почти 6 лет назад

Security update for qemu

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-9946

Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.

CVSS3: 7.5
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-9946

Cloud Native Computing Foundation (CNCF) CNI (Container Networking Int ...

CVSS3: 7.5
0%
Низкий
около 6 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0310-1

Security update for buildah, libcontainers-common, podman

больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2020:2106-1

Security update for buildah

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2020:3423-1

Security update for buildah

больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2022:0770-1

Security update for buildah

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:0770-1

Security update for buildah

больше 3 лет назад
ubuntu логотип
CVE-2019-14378

ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.

CVSS3: 8.8
7%
Низкий
почти 6 лет назад
redhat логотип
CVE-2019-14378

ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.

CVSS3: 7
7%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-14378

ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.

CVSS3: 8.8
7%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-14378

ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overf ...

CVSS3: 8.8
7%
Низкий
почти 6 лет назад
github логотип
GHSA-6g96-g4m6-hw69

Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
suse-cvrf логотип
openSUSE-SU-2020:0554-1

Security update for kubernetes

около 5 лет назад
oracle-oval логотип
ELSA-2019-4593

ELSA-2019-4593: kubernetes kubeadm-upgrade kubeadm-ha-setup security update (IMPORTANT)

около 6 лет назад
github логотип
GHSA-qvqc-h5c8-h785

ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.

7%
Низкий
около 3 лет назад
fstec логотип
BDU:2019-03648

Уязвимость функции ip_reass из ip_input.c библиотеки TCP-IP эмулятора Libslirp, позволяющая нарушителю получить несанкционированный доступ к информации, вызвать отказ в обслуживании или оказать воздействие на доступность информации

CVSS3: 8.8
7%
Низкий
почти 6 лет назад
oracle-oval логотип
ELSA-2020-0366

ELSA-2020-0366: qemu-kvm security, bug fix, and enhancement update (IMPORTANT)

больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2059-1

Security update for qemu

почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2353-1

Security update for qemu

почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2246-1

Security update for qemu

почти 6 лет назад

Уязвимостей на страницу