Zeros312
CVE-1999-0236 | 1999-Sep | ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs. | 0 | Important | 2025-10-01 23:10:48+03:00 | 2020-09-25 00:00:00+03:00 | Important | 500cf164743b81270f3e02f13c6cb5a0d141610d66cfcc40376c8204800f7ffc | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '1999-Sep', 'vulnerability': {'CVE': 'CVE-1999-0236', 'CWE': [{'ID': 'CWE-200', 'Value': 'Exposure of Sensitive Information to an Unauthorized Actor'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19248-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19248-16820'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19248-16820'], 'FixedBuild': '2.4.46-2', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19248-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [{'Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N', 'BaseScore': 7.5, 'ProductID': ['19248-16820'], 'TemporalScore': 7.5, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19248-16820']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '1999-Sep'}, 'Alias': {'Value': '1999-Sep'}}, 'RevisionHistory': [{'Date': '2025-10-01T23:10:48', 'Number': '4', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-10-01T23:10:48', 'InitialReleaseDate': '1999-09-02T00:00:00'}} |
CVE-1999-0475 | 1999-Sep | A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail. | 0 | Low | 2025-10-01 23:10:48+03:00 | 2025-10-01 23:10:48+03:00 | Low | 87e804f146fb3b37ff433aa4b6966c7c9e82b0b4be1e370e2ccbeb5cd02de798 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '1999-Sep', 'vulnerability': {'CVE': 'CVE-1999-0475', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail.'}, 'Ordinal': '2', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16902-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16902-16823'], 'Description': {'Value': 'Low'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16902-16823'], 'FixedBuild': '3.22-53', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16902-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16902-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:48', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '1999-Sep'}, 'Alias': {'Value': '1999-Sep'}}, 'RevisionHistory': [{'Date': '2025-10-01T23:10:48', 'Number': '4', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-10-01T23:10:48', 'InitialReleaseDate': '1999-09-02T00:00:00'}} |
CVE-1999-0150 | 1999-Sep | The Perl fingerd program allows arbitrary command execution from remote users. | 0 | Important | 2025-10-01 23:10:48+03:00 | 2021-12-01 00:00:00+03:00 | Important | f203d4b66859f92aa93497a4ca6d903b7cf002f0632a8368b2e3c5fad9d4184a | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '1999-Sep', 'vulnerability': {'CVE': 'CVE-1999-0150', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The Perl fingerd program allows arbitrary command execution from remote users.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19246-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19247-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19246-16820'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19247-16823'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19246-16820', '19247-16823'], 'FixedBuild': '0.17-4', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19246-16820', '19247-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19246-16820', '19247-16823']}], 'RevisionHistory': [{'Date': '2021-12-01T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2021-12-16T00:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Added finger to CBL-Mariner 2.0</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '1999-Sep'}, 'Alias': {'Value': '1999-Sep'}}, 'RevisionHistory': [{'Date': '2025-10-01T23:10:48', 'Number': '4', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-10-01T23:10:48', 'InitialReleaseDate': '1999-09-02T00:00:00'}} |
CVE-1999-0612 | 1999-Sep | A version of finger is running that exposes valid user information to any entity on the network. | 0 | Low | 2025-10-01 23:10:48+03:00 | 2021-12-01 00:00:00+03:00 | Low | 0ee767087c2dd02181cd8b25b401401293d1b51917029d40b804300999f164fe | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '1999-Sep', 'vulnerability': {'CVE': 'CVE-1999-0612', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'A version of finger is running that exposes valid user information to any entity on the network.'}, 'Ordinal': '3', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19246-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19246-16820'], 'Description': {'Value': 'Low'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19246-16820'], 'FixedBuild': '0.17-4', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19246-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19246-16820']}], 'RevisionHistory': [{'Date': '2021-12-01T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2021-12-16T00:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Added finger to CBL-Mariner 2.0</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '1999-Sep'}, 'Alias': {'Value': '1999-Sep'}}, 'RevisionHistory': [{'Date': '2025-10-01T23:10:48', 'Number': '4', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-10-01T23:10:48', 'InitialReleaseDate': '1999-09-02T00:00:00'}} |
CVE-1999-0656 | 2000-Feb | The ugidd RPC interface by design allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names. | 0 | Moderate | 2026-02-19 01:07:19+03:00 | 2020-09-25 00:00:00+03:00 | Moderate | b773133b885582a6c0ad0aae4dad450dfb284417216f1e5215136b3b796d12c2 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2000-Feb', 'vulnerability': {'CVE': 'CVE-1999-0656', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The ugidd RPC interface by design allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names.'}, 'Ordinal': '2', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16919-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16920-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17065-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19529-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16919-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16920-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17065-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19529-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16919-16820'], 'FixedBuild': '-', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16919-16820'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16920-16823'], 'FixedBuild': '5.10.78.1-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16920-16823'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['17065-17084', '19529-17084'], 'FixedBuild': '6.6.35.1-4', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['17065-17084', '19529-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16919-16820', '16920-16823', '17065-17084', '19529-17084']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2021-12-16T00:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Added kernel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-08-15T00:00:00', 'Number': '1.2', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2026-02-19T01:07:19', 'Number': '1.3', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2000-Feb'}, 'Alias': {'Value': '2000-Feb'}}, 'RevisionHistory': [{'Date': '2026-02-19T01:07:19', 'Number': '5', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-19T01:07:19', 'InitialReleaseDate': '2000-02-02T00:00:00'}} |
CVE-1999-0163 | 2000-Feb | In older versions of Sendmail, an attacker could use a pipe character to execute root commands. | 0 | Important | 2026-02-19 01:07:19+03:00 | 2025-10-01 23:10:47+03:00 | Important | d458d716b980168b211ffa7c3146447b980fc14551511c9dd1cf9b20ef31a418 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2000-Feb', 'vulnerability': {'CVE': 'CVE-1999-0163', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'In older versions of Sendmail, an attacker could use a pipe character to execute root commands.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['18884-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['18884-16823'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['18884-16823'], 'FixedBuild': '8.15.2-46', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['18884-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['18884-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:47', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2000-Feb'}, 'Alias': {'Value': '2000-Feb'}}, 'RevisionHistory': [{'Date': '2026-02-19T01:07:19', 'Number': '5', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-19T01:07:19', 'InitialReleaseDate': '2000-02-02T00:00:00'}} |
CVE-1999-0524 | 2000-Feb | ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts. | 0 | Low | 2026-02-19 01:07:19+03:00 | 2020-09-25 00:00:00+03:00 | Low | fad6c77d397cfba61d722f76bf4d0488c2003cb413ccdf93c780e2575dd6511c | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2000-Feb', 'vulnerability': {'CVE': 'CVE-1999-0524', 'CWE': [{'ID': 'CWE-200', 'Value': 'Exposure of Sensitive Information to an Unauthorized Actor'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16919-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16920-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16919-16820'], 'Description': {'Value': 'Low'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16920-16823'], 'Description': {'Value': 'Low'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16919-16820'], 'FixedBuild': '-', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16919-16820'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16920-16823'], 'FixedBuild': '5.10.78.1-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16920-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16919-16820', '16920-16823']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2021-12-16T00:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Added kernel to CBL-Mariner 2.0</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2000-Feb'}, 'Alias': {'Value': '2000-Feb'}}, 'RevisionHistory': [{'Date': '2026-02-19T01:07:19', 'Number': '5', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-19T01:07:19', 'InitialReleaseDate': '2000-02-02T00:00:00'}} |
CVE-1999-0428 | 2000-Jan | OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls. | 0 | Important | 2026-02-18 01:04:13+03:00 | 2020-09-25 00:00:00+03:00 | Important | 24460d9933074b7a93f25ddd98da34966fea612fc14c8dacd8d76cf8a9b855f2 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2000-Jan', 'vulnerability': {'CVE': 'CVE-1999-0428', 'CWE': [{'ID': 'CWE-384', 'Value': 'Session Fixation'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16878-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16878-16820'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16878-16820'], 'FixedBuild': '-', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16878-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16878-16820']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2000-Jan'}, 'Alias': {'Value': '2000-Jan'}}, 'RevisionHistory': [{'Date': '2026-02-18T01:04:13', 'Number': '4', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T01:04:13', 'InitialReleaseDate': '2000-01-02T00:00:00'}} |
CVE-1999-0901 | 2000-Jan | ypserv allows a local user to modify the GECOS and login shells of other users. | 0 | Important | 2026-02-18 01:04:13+03:00 | 2025-10-01 23:10:48+03:00 | Important | 98713bbef578db09107727356a6e3f8e1220e4c2fff66b970bc77c4ad996d207 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2000-Jan', 'vulnerability': {'CVE': 'CVE-1999-0901', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'ypserv allows a local user to modify the GECOS and login shells of other users.'}, 'Ordinal': '2', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19249-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19249-16823'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19249-16823'], 'FixedBuild': '4.1-4', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19249-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19249-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:48', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2000-Jan'}, 'Alias': {'Value': '2000-Jan'}}, 'RevisionHistory': [{'Date': '2026-02-18T01:04:13', 'Number': '4', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T01:04:13', 'InitialReleaseDate': '2000-01-02T00:00:00'}} |
CVE-1999-0902 | 2000-Jan | ypserv allows local administrators to modify password tables. | 0 | Important | 2026-02-18 01:04:13+03:00 | 2025-10-01 23:10:48+03:00 | Important | 246bacbe3662948ae83e00f4ca2e8d0d4c17bb5a14dd7dff187d49f681245b94 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2000-Jan', 'vulnerability': {'CVE': 'CVE-1999-0902', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'ypserv allows local administrators to modify password tables.'}, 'Ordinal': '3', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19249-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19249-16823'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19249-16823'], 'FixedBuild': '4.1-4', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19249-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19249-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:48', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2000-Jan'}, 'Alias': {'Value': '2000-Jan'}}, 'RevisionHistory': [{'Date': '2026-02-18T01:04:13', 'Number': '4', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T01:04:13', 'InitialReleaseDate': '2000-01-02T00:00:00'}} |
CVE-1999-0817 | 2000-Jan | Lynx WWW client allows a remote attacker to specify command-line parameters which Lynx uses when calling external programs to handle certain protocols, e.g. telnet. | 0 | Critical | 2026-02-18 01:04:13+03:00 | 2025-09-03 19:34:58+03:00 | Critical | 92d1b6a5bcd04e26050f9388d21c2e9ab9fceb6a656ecf46d30fcc89ac12725c | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2000-Jan', 'vulnerability': {'CVE': 'CVE-1999-0817', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Lynx WWW client allows a remote attacker to specify command-line parameters which Lynx uses when calling external programs to handle certain protocols, e.g. telnet.'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16881-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19738-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16881-16823'], 'Description': {'Value': 'Critical'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19738-17084'], 'Description': {'Value': 'Critical'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16881-16823'], 'FixedBuild': '2.9.0~dev.9-5', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16881-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16881-16823', '19738-17084']}], 'RevisionHistory': [{'Date': '2025-09-03T19:34:58', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2026-02-18T01:04:13', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2000-Jan'}, 'Alias': {'Value': '2000-Jan'}}, 'RevisionHistory': [{'Date': '2026-02-18T01:04:13', 'Number': '4', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T01:04:13', 'InitialReleaseDate': '2000-01-02T00:00:00'}} |
CVE-1999-0965 | 2000-Jan | Race condition in xterm allows local users to modify arbitrary files via the logging option. | 0 | Moderate | 2026-02-18 01:04:13+03:00 | 2025-10-01 23:10:48+03:00 | Moderate | ed7b74fe99d6b75b752e383e8cea18f1452de130be1eed83721ca6d2344c7757 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2000-Jan', 'vulnerability': {'CVE': 'CVE-1999-0965', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Race condition in xterm allows local users to modify arbitrary files via the logging option.'}, 'Ordinal': '4', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['18330-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['18330-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['18330-16823'], 'FixedBuild': '380-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['18330-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['18330-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:48', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2000-Jan'}, 'Alias': {'Value': '2000-Jan'}}, 'RevisionHistory': [{'Date': '2026-02-18T01:04:13', 'Number': '4', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T01:04:13', 'InitialReleaseDate': '2000-01-02T00:00:00'}} |
CVE-1999-0145 | 2000-Oct | Sendmail WIZ command enabled, allowing root access. | 0 | Important | 2025-10-01 23:10:10+03:00 | 2025-10-01 23:10:10+03:00 | Important | e9e2dfa142c1021c201251b52779c5d36378d2834e3d6f52c181c3c4da77ae79 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2000-Oct', 'vulnerability': {'CVE': 'CVE-1999-0145', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Sendmail WIZ command enabled, allowing root access.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['18884-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['18884-16823'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['18884-16823'], 'FixedBuild': '8.15.2-46', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['18884-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['18884-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:10', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2000-Oct'}, 'Alias': {'Value': '2000-Oct'}}, 'RevisionHistory': [{'Date': '2025-10-01T23:10:10', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-10-01T23:10:10', 'InitialReleaseDate': '2000-10-02T00:00:00'}} |
CVE-2000-0803 | 2001-May | GNU Groff uses the current working directory to find a device description file which allows a local user to gain additional privileges by including a malicious postpro directive in the description file which is executed when another user runs groff. | 0 | 2020-09-25 00:00:00+03:00 | 2020-09-25 00:00:00+03:00 | 00519d033d09f6854d764fbc2a14ad157f16500ecf2ec986e16d9da3c5b0b64a | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2001-May', 'vulnerability': {'CVE': 'CVE-2000-0803', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'GNU Groff uses the current working directory to find a device description file which allows a local user to gain additional privileges by including a malicious postpro directive in the description file which is executed when another user runs groff.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13570-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13571-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13572-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13573-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13570-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13571-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13572-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13573-12138'], 'Description': {}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['13570-12137', '13571-12137', '13572-12138', '13573-12138'], 'FixedBuild': '1.22.3-5', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['13570-12137', '13571-12137', '13572-12138', '13573-12138'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['13570-12137', '13571-12137', '13572-12138', '13573-12138']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2001-May'}, 'Alias': {'Value': '2001-May'}}, 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2020-09-25T00:00:00', 'InitialReleaseDate': '2001-05-02T00:00:00'}} | ||
CVE-1999-1412 | 2001-Sep | A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs which generates a large number of processes. | 0 | Moderate | 2020-09-25 00:00:00+03:00 | 2020-09-25 00:00:00+03:00 | Moderate | fc4b1ad08eee6f453cc46efcbbe5b67e99794c1592b0e60eaf1140a2b2bf8ff6 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2001-Sep', 'vulnerability': {'CVE': 'CVE-1999-1412', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs which generates a large number of processes.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19248-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19248-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19248-16820'], 'FixedBuild': '2.4.46-2', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19248-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19248-16820']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2001-Sep'}, 'Alias': {'Value': '2001-Sep'}}, 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2020-09-25T00:00:00', 'InitialReleaseDate': '2001-09-02T00:00:00'}} |
CVE-1999-1090 | 2002-Mar | The default configuration of NCSA Telnet package for Macintosh and PC enables FTP, even though it does not include an "ftp=yes" line, which allows remote attackers to read and modify arbitrary files. | 0 | Important | 2026-01-04 14:35:13+03:00 | 2025-10-01 23:10:49+03:00 | Important | 79d6f89936c9644649305d40efd37d49823bf57552bce6780275d6e26a280ed4 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2002-Mar', 'vulnerability': {'CVE': 'CVE-1999-1090', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The default configuration of NCSA Telnet package for Macintosh and PC enables FTP, even though it does not include an "ftp=yes" line, which allows remote attackers to read and modify arbitrary files.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19250-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19250-16823'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19250-16823'], 'FixedBuild': '0.17-81', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19250-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19250-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:49', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2002-Mar'}, 'Alias': {'Value': '2002-Mar'}}, 'RevisionHistory': [{'Date': '2026-01-04T14:35:13', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-01-04T14:35:13', 'InitialReleaseDate': '2002-03-02T00:00:00'}} |
CVE-2002-0129 | 2002-Mar | efax 0.9 and earlier, when installed setuid root, allows local users to read arbitrary files via the -d option, which prints the contents of the file in a warning message. | 0 | Low | 2026-01-04 14:35:13+03:00 | 2025-10-01 23:10:49+03:00 | Low | 7ccc28aef461faecace4be8ca781d26a77873a5ab739fe5ce58d3a85596222f1 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2002-Mar', 'vulnerability': {'CVE': 'CVE-2002-0129', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'efax 0.9 and earlier, when installed setuid root, allows local users to read arbitrary files via the -d option, which prints the contents of the file in a warning message.'}, 'Ordinal': '2', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19636-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19636-16823'], 'Description': {'Value': 'Low'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19636-16823'], 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19636-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19636-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:49', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2002-Mar'}, 'Alias': {'Value': '2002-Mar'}}, 'RevisionHistory': [{'Date': '2026-01-04T14:35:13', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-01-04T14:35:13', 'InitialReleaseDate': '2002-03-02T00:00:00'}} |
CVE-2002-0130 | 2002-Mar | Buffer overflow in efax 0.9 and earlier, when installed setuid root, allows local users to execute arbitrary code via a long -x argument. | 0 | Important | 2026-01-04 14:35:13+03:00 | 2025-10-01 23:10:49+03:00 | Important | 5d4913be85f2d1fb5b91b8c2da667e7c81581ae5ba5a8c046d89a398825b5a5a | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2002-Mar', 'vulnerability': {'CVE': 'CVE-2002-0130', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Buffer overflow in efax 0.9 and earlier, when installed setuid root, allows local users to execute arbitrary code via a long -x argument.'}, 'Ordinal': '3', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19636-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19636-16823'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19636-16823'], 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19636-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19636-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:49', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2002-Mar'}, 'Alias': {'Value': '2002-Mar'}}, 'RevisionHistory': [{'Date': '2026-01-04T14:35:13', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-01-04T14:35:13', 'InitialReleaseDate': '2002-03-02T00:00:00'}} |
CVE-2000-0006 | 2002-Mar | strace allows local users to read arbitrary files via memory mapped file names. | 0 | Low | 2026-01-04 14:35:13+03:00 | 2025-09-03 21:59:27+03:00 | Low | 8a58db6315657a3b23bd6df3c0f8b5cfb3dc8389697fc305f49d9ddbb6b4e132 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2002-Mar', 'vulnerability': {'CVE': 'CVE-2000-0006', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'strace allows local users to read arbitrary files via memory mapped file names.'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['20121-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19635-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['20121-17084'], 'Description': {'Value': 'Low'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19635-16823'], 'Description': {'Value': 'Low'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19635-16823'], 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19635-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['20121-17084', '19635-16823']}], 'RevisionHistory': [{'Date': '2025-09-03T21:59:27', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2026-01-04T14:35:13', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2002-Mar'}, 'Alias': {'Value': '2002-Mar'}}, 'RevisionHistory': [{'Date': '2026-01-04T14:35:13', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-01-04T14:35:13', 'InitialReleaseDate': '2002-03-02T00:00:00'}} |
CVE-2002-0318 | 2003-Apr | FreeRADIUS RADIUS server allows remote attackers to cause a denial of service (CPU consumption) via a flood of Access-Request packets. | 0 | Moderate | 2025-10-01 23:10:50+03:00 | 2025-10-01 23:10:50+03:00 | Moderate | 8aecb3c7545785794b07ab6278afba4c75d4d642fed1988ced0513306df26d9c | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2003-Apr', 'vulnerability': {'CVE': 'CVE-2002-0318', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'FreeRADIUS RADIUS server allows remote attackers to cause a denial of service (CPU consumption) via a flood of Access-Request packets.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19637-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19637-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19637-16823'], 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19637-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19637-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:50', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2003-Apr'}, 'Alias': {'Value': '2003-Apr'}}, 'RevisionHistory': [{'Date': '2025-10-01T23:10:50', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-10-01T23:10:50', 'InitialReleaseDate': '2003-04-02T00:00:00'}} |
CVE-2005-2069 | 2005-Jun | pam_ldap and nss_ldap when used with OpenLDAP and connecting to a slave using TLS does not use TLS for the subsequent connection if the client is referred to a master which may cause a password to be sent in cleartext and allows remote attackers to sniff the password. | 0 | 2020-09-25 00:00:00+03:00 | 2020-09-25 00:00:00+03:00 | 2a040d72475d130c717b73f9736761a2f94fdf3276a4654da356b76a3847c32b | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2005-Jun', 'vulnerability': {'CVE': 'CVE-2005-2069', 'CWE': [{'ID': 'CWE-319', 'Value': 'Cleartext Transmission of Sensitive Information'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'pam_ldap and nss_ldap when used with OpenLDAP and connecting to a slave using TLS does not use TLS for the subsequent connection if the client is referred to a master which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13462-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13463-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13464-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13465-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13462-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13463-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13464-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13465-12138'], 'Description': {}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['13462-12137', '13463-12137', '13464-12138', '13465-12138'], 'FixedBuild': '2.4.57-2', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['13462-12137', '13463-12137', '13464-12138', '13465-12138'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['13462-12137', '13463-12137', '13464-12138', '13465-12138']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2005-Jun'}, 'Alias': {'Value': '2005-Jun'}}, 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2020-09-25T00:00:00', 'InitialReleaseDate': '2005-06-02T00:00:00'}} | ||
CVE-2007-2650 | 2007-May | The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (resource consumption) via an OLE2 file with (1) a large property size or (2) a loop in the FAT file block chain that triggers an infinite loop as demonstrated via a crafted DOC file. | 0 | 2026-02-18 01:21:20+03:00 | 2020-10-25 00:00:00+03:00 | 367ebb76bc32aca3cfcc398f7e91bbc308cb521195b9726f3b5fc9245d5a0673 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2007-May', 'vulnerability': {'CVE': 'CVE-2007-2650', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (resource consumption) via an OLE2 file with (1) a large property size or (2) a loop in the FAT file block chain that triggers an infinite loop as demonstrated via a crafted DOC file.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13841-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13842-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13843-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13844-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13841-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13842-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13843-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13844-12138'], 'Description': {}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['13841-12137', '13842-12137', '13843-12138', '13844-12138'], 'FixedBuild': '0.103.2-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['13841-12137', '13842-12137', '13843-12138', '13844-12138'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['13841-12137', '13842-12137', '13843-12138', '13844-12138']}], 'RevisionHistory': [{'Date': '2020-10-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2007-May'}, 'Alias': {'Value': '2007-May'}}, 'RevisionHistory': [{'Date': '2026-02-18T01:21:20', 'Number': '5', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T01:21:20', 'InitialReleaseDate': '2007-05-02T00:00:00'}} | ||
CVE-2007-4998 | 2008-Jan | cp when running with an option to preserve symlinks on multiple OSes allows local user-assisted attackers to overwrite arbitrary files via a symlink attack using crafted directories containing multiple source files that are copied to the same destination. | 0 | Moderate | 2026-02-19 01:07:31+03:00 | 2026-02-19 01:07:31+03:00 | Moderate | 64e35882e9c78301d386246e7d0e8ffc268183a49be11cb0bbfc12bc1ae06681 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2008-Jan', 'vulnerability': {'CVE': 'CVE-2007-4998', 'CWE': [{'ID': 'CWE-59', 'Value': 'Improper Link Resolution Before File Access ('Link Following')'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'cp when running with an option to preserve symlinks on multiple OSes allows local user-assisted attackers to overwrite arbitrary files via a symlink attack using crafted directories containing multiple source files that are copied to the same destination.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16919-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16920-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17065-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19529-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16919-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16920-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17065-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19529-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16919-16820'], 'FixedBuild': '-', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16919-16820'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16920-16823'], 'FixedBuild': '5.10.78.1-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16920-16823'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['17065-17084', '19529-17084'], 'FixedBuild': '6.6.35.1-4', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['17065-17084', '19529-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16919-16820', '16920-16823', '17065-17084', '19529-17084']}], 'RevisionHistory': [{'Date': '2026-02-19T01:07:31', 'Number': '1.3', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2021-12-16T00:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Added kernel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-08-15T00:00:00', 'Number': '1.2', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2008-Jan'}, 'Alias': {'Value': '2008-Jan'}}, 'RevisionHistory': [{'Date': '2026-02-19T01:07:31', 'Number': '4', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-19T01:07:31', 'InitialReleaseDate': '2008-01-02T00:00:00'}} |
CVE-2019-1547 | 2019-Sep | ECDSA remote timing attack | 0 | Moderate | 2026-04-30 01:54:38+03:00 | 2025-09-04 00:10:29+03:00 | Moderate | aa9005b2809033d5f7e0a7df02bf32d1f917e5ef54f20c19a69510dbbfba1910 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2019-Sep', 'vulnerability': {'CVE': 'CVE-2019-1547', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'openssl', 'Value': 'openssl', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'ECDSA remote timing attack'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['21108-17086'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['21249-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['21266-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17012-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17013-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['20115-17086'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['21183-17086'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['21184-17086'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['21185-17086'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['21110-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['21123-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['21108-17086'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['21249-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['21266-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17012-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17013-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['20115-17086'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['21183-17086'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['21184-17086'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['21185-17086'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['21110-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['21123-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [], 'CVSSScoreSets': [{'Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N', 'BaseScore': 4.7, 'ProductID': ['21108-17086'], 'TemporalScore': 4.7, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N', 'BaseScore': 4.7, 'ProductID': ['21249-17084'], 'TemporalScore': 4.7, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N', 'BaseScore': 4.7, 'ProductID': ['21266-17084'], 'TemporalScore': 4.7, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N', 'BaseScore': 4.7, 'ProductID': ['17012-17084'], 'TemporalScore': 4.7, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N', 'BaseScore': 4.7, 'ProductID': ['17013-17084'], 'TemporalScore': 4.7, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N', 'BaseScore': 4.7, 'ProductID': ['20115-17086'], 'TemporalScore': 4.7, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N', 'BaseScore': 4.7, 'ProductID': ['21183-17086'], 'TemporalScore': 4.7, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N', 'BaseScore': 4.7, 'ProductID': ['21184-17086'], 'TemporalScore': 4.7, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N', 'BaseScore': 4.7, 'ProductID': ['21185-17086'], 'TemporalScore': 4.7, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N', 'BaseScore': 4.7, 'ProductID': ['21110-17084'], 'TemporalScore': 4.7, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N', 'BaseScore': 4.7, 'ProductID': ['21123-17084'], 'TemporalScore': 4.7, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['21108-17086', '21249-17084', '21266-17084', '17012-17084', '17013-17084', '20115-17086', '21183-17086', '21184-17086', '21185-17086', '21110-17084', '21123-17084']}], 'RevisionHistory': [{'Date': '2025-09-04T00:10:29', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2026-02-19T01:37:05', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2026-04-29T01:09:27', 'Number': '2.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2026-04-29T15:00:48', 'Number': '3.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2026-04-30T01:54:38', 'Number': '4.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2019-Sep'}, 'Alias': {'Value': '2019-Sep'}}, 'RevisionHistory': [{'Date': '2026-04-30T01:54:38', 'Number': '29', 'Description': {'Value': 'September 2019 Security Updates'}}], 'CurrentReleaseDate': '2026-04-30T01:54:38', 'InitialReleaseDate': '2019-09-10T07:00:00'}} |
CVE-2005-0469 | 2005-Mar | Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands. | 0 | Important | 2025-10-01 23:10:50+03:00 | 2025-10-01 23:10:50+03:00 | Important | b5b604bea378a305f386b3120791ce0dc2adf288f7294f25f6c738eeb9c6bd8f | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2005-Mar', 'vulnerability': {'CVE': 'CVE-2005-0469', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19638-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19638-16823'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19638-16823'], 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19638-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19638-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:50', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2005-Mar'}, 'Alias': {'Value': '2005-Mar'}}, 'RevisionHistory': [{'Date': '2025-10-01T23:10:50', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-10-01T23:10:50', 'InitialReleaseDate': '2005-03-02T00:00:00'}} |
CVE-2005-0868 | 2005-Mar | AS/400 Telnet 5250 terminal emulation clients, as implemented by (1) IBM client access, (2) Bosanova, (3) PowerTerm, (4) Mochasoft, and possibly other emulations, allows malicious AS/400 servers to execute arbitrary commands via a STRPCO (Start PC Organizer) command followed by STRPCCMD (Start PC command), as demonstrated by creating a backdoor account using REXEC. | 0 | Important | 2025-10-01 23:10:50+03:00 | 2025-10-01 23:10:50+03:00 | Important | 05d731d99f0d9e243b9c195817a936850951f87805da41c0acfa1eadc784ef0a | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2005-Mar', 'vulnerability': {'CVE': 'CVE-2005-0868', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'AS/400 Telnet 5250 terminal emulation clients, as implemented by (1) IBM client access, (2) Bosanova, (3) PowerTerm, (4) Mochasoft, and possibly other emulations, allows malicious AS/400 servers to execute arbitrary commands via a STRPCO (Start PC Organizer) command followed by STRPCCMD (Start PC command), as demonstrated by creating a backdoor account using REXEC.'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19639-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19639-16823'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19639-16823'], 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19639-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19639-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:50', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2005-Mar'}, 'Alias': {'Value': '2005-Mar'}}, 'RevisionHistory': [{'Date': '2025-10-01T23:10:50', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-10-01T23:10:50', 'InitialReleaseDate': '2005-03-02T00:00:00'}} |
CVE-2006-5201 | 2006-Oct | Multiple packages on Sun Solaris including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier SDK and JRE 1.4.x up to 1.4.2_12 and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice when using an RSA key with exponent 3 removes PKCS-1 padding before generating a hash which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents these products from correctly verifying X.509 and other certificates that use PKCS #1. | 0 | 2020-09-25 00:00:00+03:00 | 2020-09-25 00:00:00+03:00 | 41425b62635995fd37980495144672b194212226d4d4421e615a582f34ac95b6 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2006-Oct', 'vulnerability': {'CVE': 'CVE-2006-5201', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Multiple packages on Sun Solaris including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier SDK and JRE 1.4.x up to 1.4.2_12 and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice when using an RSA key with exponent 3 removes PKCS-1 padding before generating a hash which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents these products from correctly verifying X.509 and other certificates that use PKCS #1.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13550-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13551-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13552-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13553-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13554-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13555-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13556-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13557-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13550-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13551-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13552-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13553-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13554-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13555-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13556-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13557-12138'], 'Description': {}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['13550-12137', '13551-12137', '13552-12137', '13553-12137', '13554-12138', '13555-12138', '13556-12138', '13557-12138'], 'FixedBuild': '3.73-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['13550-12137', '13551-12137', '13552-12137', '13553-12137', '13554-12138', '13555-12138', '13556-12138', '13557-12138'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['13550-12137', '13551-12137', '13552-12137', '13553-12137', '13554-12138', '13555-12138', '13556-12138', '13557-12138']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2006-Oct'}, 'Alias': {'Value': '2006-Oct'}}, 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2020-09-25T00:00:00', 'InitialReleaseDate': '2006-10-02T00:00:00'}} | ||
CVE-2007-4559 | 2007-Aug | Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive a related issue to CVE-2001-1267. | 0 | Moderate | 2025-05-27 00:00:00+03:00 | 2024-09-26 00:00:00+03:00 | Moderate | 45b2ce83d08abcd7ff4f799d4c74a1d36c2e7afd6ba98bf2eede092ad3bae9fe | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2007-Aug', 'vulnerability': {'CVE': 'CVE-2007-4559', 'CWE': [{'ID': 'CWE-22', 'Value': 'Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive a related issue to CVE-2001-1267.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['18458-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16906-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17386-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16905-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['18458-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16906-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17386-16823'], 'Description': {'Value': 'Critical'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16905-16823'], 'Description': {'Value': 'Critical'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['18458-16820'], 'FixedBuild': '3.7.16-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['18458-16820'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16906-16820'], 'FixedBuild': '2.7.18-5', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16906-16820'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['17386-16823'], 'FixedBuild': '3.9.19-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['17386-16823'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16905-16823'], 'FixedBuild': '2.7.18-8', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16905-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [{'Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'BaseScore': 9.8, 'ProductID': ['18458-16820'], 'TemporalScore': 9.8, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'BaseScore': 9.8, 'ProductID': ['16906-16820'], 'TemporalScore': 9.8, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'BaseScore': 9.8, 'ProductID': ['17386-16823'], 'TemporalScore': 9.8, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'BaseScore': 9.8, 'ProductID': ['16905-16823'], 'TemporalScore': 9.8, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['18458-16820', '16906-16820', '17386-16823', '16905-16823']}], 'RevisionHistory': [{'Date': '2024-09-26T00:00:00', 'Number': '8.8', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-29T00:00:00', 'Number': '9.1', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-02T00:00:00', 'Number': '9.4', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-07T00:00:00', 'Number': '9.9', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-09T00:00:00', 'Number': '10.1', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-15T00:00:00', 'Number': '10.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-17T00:00:00', 'Number': '10.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-20T00:00:00', 'Number': '11.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-22T00:00:00', 'Number': '11.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-24T00:00:00', 'Number': '11.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-25T00:00:00', 'Number': '11.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-26T00:00:00', 'Number': '11.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-28T00:00:00', 'Number': '12.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-30T00:00:00', 'Number': '12.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-04T00:00:00', 'Number': '12.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-05T00:00:00', 'Number': '12.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-06T00:00:00', 'Number': '12.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-08T00:00:00', 'Number': '13.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-09T00:00:00', 'Number': '13.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-10T00:00:00', 'Number': '13.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-11T00:00:00', 'Number': '13.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-13T00:00:00', 'Number': '13.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-15T00:00:00', 'Number': '13.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-16T00:00:00', 'Number': '13.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-19T00:00:00', 'Number': '14.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-20T00:00:00', 'Number': '14.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-23T00:00:00', 'Number': '14.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-24T00:00:00', 'Number': '14.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-26T00:00:00', 'Number': '14.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-28T00:00:00', 'Number': '14.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-29T00:00:00', 'Number': '15.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-01T00:00:00', 'Number': '15.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-04T00:00:00', 'Number': '15.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-07T00:00:00', 'Number': '15.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-08T00:00:00', 'Number': '15.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-11T00:00:00', 'Number': '16.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-15T00:00:00', 'Number': '16.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-16T00:00:00', 'Number': '16.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-18T00:00:00', 'Number': '16.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-20T00:00:00', 'Number': '17.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-21T00:00:00', 'Number': '17.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-29T00:00:00', 'Number': '17.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-30T00:00:00', 'Number': '18.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-31T00:00:00', 'Number': '18.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2025-01-02T00:00:00', 'Number': '18.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2025-01-03T00:00:00', 'Number': '18.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2025-01-05T00:00:00', 'Number': '18.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2025-01-06T00:00:00', 'Number': '18.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2025-01-07T00:00:00', 'Number': '18.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2025-01-08T00:00:00', 'Number': '18.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2025-01-09T00:00:00', 'Number': '19.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2025-01-10T00:00:00', 'Number': '19.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2025-01-12T00:00:00', 'Number': '19.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2025-01-15T00:00:00', 'Number': '19.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2025-01-16T00:00:00', 'Number': '19.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2025-01-17T00:00:00', 'Number': '19.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2025-01-18T00:00:00', 'Number': '19.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-01-19T00:00:00', 'Number': '19.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-01-22T00:00:00', 'Number': '20.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-01-27T00:00:00', 'Number': '20.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-01-28T00:00:00', 'Number': '20.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-01-29T00:00:00', 'Number': '20.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-01-30T00:00:00', 'Number': '20.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-01T00:00:00', 'Number': '21.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-02T00:00:00', 'Number': '21.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-03T00:00:00', 'Number': '21.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-04T00:00:00', 'Number': '21.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-05T00:00:00', 'Number': '21.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-07T00:00:00', 'Number': '21.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-08T00:00:00', 'Number': '21.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-12T00:00:00', 'Number': '22.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-17T00:00:00', 'Number': '22.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-19T00:00:00', 'Number': '22.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-23T00:00:00', 'Number': '23.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-24T00:00:00', 'Number': '23.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-26T00:00:00', 'Number': '23.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-03T00:00:00', 'Number': '23.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-05T00:00:00', 'Number': '24.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-09T00:00:00', 'Number': '24.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-10T00:00:00', 'Number': '24.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-11T00:00:00', 'Number': '24.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-12T00:00:00', 'Number': '24.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-13T00:00:00', 'Number': '24.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-21T00:00:00', 'Number': '25.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-23T00:00:00', 'Number': '25.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-28T00:00:00', 'Number': '26.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-31T00:00:00', 'Number': '26.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-01T00:00:00', 'Number': '26.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-05T00:00:00', 'Number': '27.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-06T00:00:00', 'Number': '27.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-07T00:00:00', 'Number': '27.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-08T00:00:00', 'Number': '27.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-09T00:00:00', 'Number': '27.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-14T00:00:00', 'Number': '27.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-16T00:00:00', 'Number': '28.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-17T00:00:00', 'Number': '28.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-26T00:00:00', 'Number': '28.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-30T00:00:00', 'Number': '29.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-02T00:00:00', 'Number': '29.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-03T00:00:00', 'Number': '29.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-06T00:00:00', 'Number': '29.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-07T00:00:00', 'Number': '29.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-08T00:00:00', 'Number': '29.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-11T00:00:00', 'Number': '30.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-15T00:00:00', 'Number': '30.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-17T00:00:00', 'Number': '30.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-21T00:00:00', 'Number': '31.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-22T00:00:00', 'Number': '31.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-25T00:00:00', 'Number': '31.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-26T00:00:00', 'Number': '31.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-27T00:00:00', 'Number': '31.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2021-12-16T00:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-06-30T07:00:00', 'Number': '1.7', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-08T00:00:00', 'Number': '1.8', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-09T00:00:00', 'Number': '1.9', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-10T00:00:00', 'Number': '2.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-12T00:00:00', 'Number': '2.1', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-13T00:00:00', 'Number': '2.2', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-14T00:00:00', 'Number': '2.3', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-15T00:00:00', 'Number': '2.4', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-16T00:00:00', 'Number': '2.5', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-17T00:00:00', 'Number': '2.6', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-19T00:00:00', 'Number': '2.7', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-20T00:00:00', 'Number': '2.8', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-21T00:00:00', 'Number': '2.9', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-22T00:00:00', 'Number': '3.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-23T00:00:00', 'Number': '3.1', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-24T00:00:00', 'Number': '3.2', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-25T00:00:00', 'Number': '3.3', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-26T00:00:00', 'Number': '3.4', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-27T00:00:00', 'Number': '3.5', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-28T00:00:00', 'Number': '3.6', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-29T00:00:00', 'Number': '3.7', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-02T00:00:00', 'Number': '3.8', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-03T00:00:00', 'Number': '3.9', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-04T00:00:00', 'Number': '4.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-05T00:00:00', 'Number': '4.1', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-06T00:00:00', 'Number': '4.2', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-07T00:00:00', 'Number': '4.3', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-08T00:00:00', 'Number': '4.4', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-09T00:00:00', 'Number': '4.5', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-10T00:00:00', 'Number': '4.6', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-11T00:00:00', 'Number': '4.7', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-12T00:00:00', 'Number': '4.8', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-15T00:00:00', 'Number': '4.9', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-16T00:00:00', 'Number': '5.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-17T00:00:00', 'Number': '5.1', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-18T00:00:00', 'Number': '5.2', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-19T00:00:00', 'Number': '5.3', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-20T00:00:00', 'Number': '5.4', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-21T00:00:00', 'Number': '5.5', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-22T00:00:00', 'Number': '5.6', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-23T00:00:00', 'Number': '5.7', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-24T00:00:00', 'Number': '5.8', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-25T00:00:00', 'Number': '5.9', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-26T00:00:00', 'Number': '6.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-27T00:00:00', 'Number': '6.1', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-28T00:00:00', 'Number': '6.2', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-29T00:00:00', 'Number': '6.3', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-30T00:00:00', 'Number': '6.4', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-31T00:00:00', 'Number': '6.5', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-01T00:00:00', 'Number': '6.6', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-02T00:00:00', 'Number': '6.7', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-03T00:00:00', 'Number': '6.8', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-05T00:00:00', 'Number': '6.9', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-06T00:00:00', 'Number': '7.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-07T00:00:00', 'Number': '7.1', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-08T00:00:00', 'Number': '7.2', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-11T00:00:00', 'Number': '7.3', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-12T00:00:00', 'Number': '7.4', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-13T00:00:00', 'Number': '7.5', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-14T00:00:00', 'Number': '7.6', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-15T00:00:00', 'Number': '7.7', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-16T00:00:00', 'Number': '7.8', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-17T00:00:00', 'Number': '7.9', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-18T00:00:00', 'Number': '8.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-19T00:00:00', 'Number': '8.1', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-20T00:00:00', 'Number': '8.2', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-21T00:00:00', 'Number': '8.3', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-22T00:00:00', 'Number': '8.4', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-23T00:00:00', 'Number': '8.5', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-24T00:00:00', 'Number': '8.6', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-25T00:00:00', 'Number': '8.7', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-27T00:00:00', 'Number': '8.9', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-28T00:00:00', 'Number': '9.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-30T00:00:00', 'Number': '9.2', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-01T00:00:00', 'Number': '9.3', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-03T00:00:00', 'Number': '9.5', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-04T00:00:00', 'Number': '9.6', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-05T00:00:00', 'Number': '9.7', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-06T00:00:00', 'Number': '9.8', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-08T00:00:00', 'Number': '10.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-10T00:00:00', 'Number': '10.2', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-11T00:00:00', 'Number': '10.3', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-12T00:00:00', 'Number': '10.4', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-13T00:00:00', 'Number': '10.5', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-14T00:00:00', 'Number': '10.6', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-16T00:00:00', 'Number': '10.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-18T00:00:00', 'Number': '11.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-19T00:00:00', 'Number': '11.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-21T00:00:00', 'Number': '11.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-23T00:00:00', 'Number': '11.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-27T00:00:00', 'Number': '11.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-29T00:00:00', 'Number': '12.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-31T00:00:00', 'Number': '12.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-01T00:00:00', 'Number': '12.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-02T00:00:00', 'Number': '12.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-07T00:00:00', 'Number': '12.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-12T00:00:00', 'Number': '13.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-14T00:00:00', 'Number': '13.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-17T00:00:00', 'Number': '13.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-18T00:00:00', 'Number': '14.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-21T00:00:00', 'Number': '14.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-25T00:00:00', 'Number': '14.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-27T00:00:00', 'Number': '14.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-11-30T00:00:00', 'Number': '15.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-02T00:00:00', 'Number': '15.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-03T00:00:00', 'Number': '15.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-05T00:00:00', 'Number': '15.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-09T00:00:00', 'Number': '15.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-10T00:00:00', 'Number': '16.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-12T00:00:00', 'Number': '16.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-13T00:00:00', 'Number': '16.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-14T00:00:00', 'Number': '16.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-17T00:00:00', 'Number': '16.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-19T00:00:00', 'Number': '16.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-22T00:00:00', 'Number': '17.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-23T00:00:00', 'Number': '17.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-24T00:00:00', 'Number': '17.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-25T00:00:00', 'Number': '17.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-26T00:00:00', 'Number': '17.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-27T00:00:00', 'Number': '17.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-12-28T00:00:00', 'Number': '17.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2025-01-01T00:00:00', 'Number': '18.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2025-01-04T00:00:00', 'Number': '18.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2025-01-11T00:00:00', 'Number': '19.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2025-01-13T00:00:00', 'Number': '19.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0\nAdded python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2025-01-20T00:00:00', 'Number': '20.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-01-21T00:00:00', 'Number': '20.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-01-23T00:00:00', 'Number': '20.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-01-24T00:00:00', 'Number': '20.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-01-25T00:00:00', 'Number': '20.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-09T00:00:00', 'Number': '21.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-10T00:00:00', 'Number': '21.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-11T00:00:00', 'Number': '21.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-13T00:00:00', 'Number': '22.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-14T00:00:00', 'Number': '22.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-15T00:00:00', 'Number': '22.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-16T00:00:00', 'Number': '22.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-18T00:00:00', 'Number': '22.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-20T00:00:00', 'Number': '22.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-21T00:00:00', 'Number': '22.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-22T00:00:00', 'Number': '23.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-25T00:00:00', 'Number': '23.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-27T00:00:00', 'Number': '23.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-02-28T00:00:00', 'Number': '23.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-01T00:00:00', 'Number': '23.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-02T00:00:00', 'Number': '23.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-04T00:00:00', 'Number': '24.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-06T00:00:00', 'Number': '24.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-08T00:00:00', 'Number': '24.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-14T00:00:00', 'Number': '24.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-15T00:00:00', 'Number': '25.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-16T00:00:00', 'Number': '25.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-17T00:00:00', 'Number': '25.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-18T00:00:00', 'Number': '25.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-19T00:00:00', 'Number': '25.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-20T00:00:00', 'Number': '25.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-22T00:00:00', 'Number': '25.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-24T00:00:00', 'Number': '25.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-25T00:00:00', 'Number': '26.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-26T00:00:00', 'Number': '26.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-27T00:00:00', 'Number': '26.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-29T00:00:00', 'Number': '26.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-03-30T00:00:00', 'Number': '26.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-03T00:00:00', 'Number': '26.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-04T00:00:00', 'Number': '26.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-11T00:00:00', 'Number': '27.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-12T00:00:00', 'Number': '27.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-13T00:00:00', 'Number': '27.7', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-15T00:00:00', 'Number': '27.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-18T00:00:00', 'Number': '28.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-19T00:00:00', 'Number': '28.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-20T00:00:00', 'Number': '28.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-21T00:00:00', 'Number': '28.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-25T00:00:00', 'Number': '28.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-28T00:00:00', 'Number': '28.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-04-29T00:00:00', 'Number': '28.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-01T00:00:00', 'Number': '29.1', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-04T00:00:00', 'Number': '29.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-05T00:00:00', 'Number': '29.5', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-09T00:00:00', 'Number': '29.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-10T00:00:00', 'Number': '30.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-12T00:00:00', 'Number': '30.2', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-13T00:00:00', 'Number': '30.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-14T00:00:00', 'Number': '30.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-16T00:00:00', 'Number': '30.6', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-18T00:00:00', 'Number': '30.8', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-19T00:00:00', 'Number': '30.9', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-20T00:00:00', 'Number': '31.0', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-23T00:00:00', 'Number': '31.3', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}, {'Date': '2025-05-24T00:00:00', 'Number': '31.4', 'Description': {'Value': '<p>Added python3 to CBL-Mariner 2.0</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2007-Aug'}, 'Alias': {'Value': '2007-Aug'}}, 'RevisionHistory': [{'Date': '2025-05-27T00:00:00', 'Number': '303', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-05-27T00:00:00', 'InitialReleaseDate': '2007-08-02T00:00:00'}} |
CVE-2007-6109 | 2007-Dec | Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function as demonstrated via a certain "emacs -batch -eval" command line. | 0 | Critical | 2026-02-18 02:01:34+03:00 | 2026-02-18 02:01:34+03:00 | Critical | 60695264dc03a3143edb075f8779b28060d8e2a05cf68fd08711081c0dfbed4e | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2007-Dec', 'vulnerability': {'CVE': 'CVE-2007-6109', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function as demonstrated via a certain "emacs -batch -eval" command line.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17168-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19239-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17557-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17168-16823'], 'Description': {'Value': 'Critical'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19239-17084'], 'Description': {'Value': 'Critical'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17557-17084'], 'Description': {'Value': 'Critical'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['17168-16823'], 'FixedBuild': '29.4-3', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['17168-16823'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19239-17084', '17557-17084'], 'FixedBuild': '29.1-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19239-17084', '17557-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['17168-16823', '19239-17084', '17557-17084']}], 'RevisionHistory': [{'Date': '2026-02-18T02:01:34', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2022-06-17T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2007-Dec'}, 'Alias': {'Value': '2007-Dec'}}, 'RevisionHistory': [{'Date': '2026-02-18T02:01:34', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T02:01:34', 'InitialReleaseDate': '2007-12-02T00:00:00'}} |
CVE-2007-6353 | 2007-Dec | Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow. | 0 | Important | 2026-02-18 02:01:34+03:00 | 2025-10-01 23:10:51+03:00 | Important | c80cd29f79cc29529eecee087b605935f464c25402bef55c287fae87ed0a4054 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2007-Dec', 'vulnerability': {'CVE': 'CVE-2007-6353', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19240-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19240-16823'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19240-16823'], 'FixedBuild': '0.28.0-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19240-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19240-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:51', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2007-Dec'}, 'Alias': {'Value': '2007-Dec'}}, 'RevisionHistory': [{'Date': '2026-02-18T02:01:34', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T02:01:34', 'InitialReleaseDate': '2007-12-02T00:00:00'}} |
CVE-2007-0086 | 2007-Jan | The Apache HTTP Server when accessed through a TCP connection with a large window size allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties who state that the large window size required by the attack is not normally supported or configured by the server or that a DDoS-style attack would accomplish the same goal | 0 | 2020-09-25 00:00:00+03:00 | 2020-09-25 00:00:00+03:00 | a58019d40da1549556957fd56badf4bdee4119bf952f048333aedca03d751bb7 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2007-Jan', 'vulnerability': {'CVE': 'CVE-2007-0086', 'CWE': [{'ID': 'CWE-400', 'Value': 'Uncontrolled Resource Consumption'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The Apache HTTP Server when accessed through a TCP connection with a large window size allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties who state that the large window size required by the attack is not normally supported or configured by the server or that a DDoS-style attack would accomplish the same goal'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13940-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13941-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13942-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13943-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13944-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13945-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13946-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13947-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13948-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13949-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13940-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13941-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13942-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13943-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13944-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13945-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13946-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13947-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13948-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13949-12138'], 'Description': {}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['13940-12137', '13941-12137', '13942-12137', '13943-12137', '13944-12137', '13945-12138', '13946-12138', '13947-12138', '13948-12138', '13949-12138'], 'FixedBuild': '2.4.46-3', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['13940-12137', '13941-12137', '13942-12137', '13943-12137', '13944-12137', '13945-12138', '13946-12138', '13947-12138', '13948-12138', '13949-12138'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['13940-12137', '13941-12137', '13942-12137', '13943-12137', '13944-12137', '13945-12138', '13946-12138', '13947-12138', '13948-12138', '13949-12138']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2007-Jan'}, 'Alias': {'Value': '2007-Jan'}}, 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2020-09-25T00:00:00', 'InitialReleaseDate': '2007-01-02T00:00:00'}} | ||
CVE-2007-3205 | 2007-Jun | The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed. NOTE: it is not clear whether this is a design limitation of the function or a bug in PHP, although it is likely to be regarded as a bug in Hardened-PHP and Suhosin. | 0 | Moderate | 2025-10-01 23:10:50+03:00 | 2025-10-01 23:10:50+03:00 | Moderate | a6031df92ae249d58b6e5080dc084066faa2bf95635e3b0b24b65da21920e1dc | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2007-Jun', 'vulnerability': {'CVE': 'CVE-2007-3205', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed. NOTE: it is not clear whether this is a design limitation of the function or a bug in PHP, although it is likely to be regarded as a bug in Hardened-PHP and Suhosin.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19238-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16917-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19238-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16917-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19238-16823'], 'FixedBuild': '8.1.32-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19238-16823'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16917-16823'], 'FixedBuild': '7.4.14-3', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16917-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19238-16823', '16917-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:50', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2007-Jun'}, 'Alias': {'Value': '2007-Jun'}}, 'RevisionHistory': [{'Date': '2025-10-01T23:10:50', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-10-01T23:10:50', 'InitialReleaseDate': '2007-06-02T00:00:00'}} |
CVE-2007-1397 | 2007-Mar | Multiple stack-based buffer overflows in the (1) ExtractRnick and (2) decrypt_topic_332 functions in FiSH allow remote attackers to execute arbitrary code via long strings. | 0 | Critical | 2025-10-01 23:10:50+03:00 | 2025-10-01 23:10:50+03:00 | Critical | a16346a96955719fcedd4dc783256a813a411fc01590ddafa6e6949945458d32 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2007-Mar', 'vulnerability': {'CVE': 'CVE-2007-1397', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Multiple stack-based buffer overflows in the (1) ExtractRnick and (2) decrypt_topic_332 functions in FiSH allow remote attackers to execute arbitrary code via long strings.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19640-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19640-16823'], 'Description': {'Value': 'Critical'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19640-16823'], 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19640-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19640-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:50', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2007-Mar'}, 'Alias': {'Value': '2007-Mar'}}, 'RevisionHistory': [{'Date': '2025-10-01T23:10:50', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-10-01T23:10:50', 'InitialReleaseDate': '2007-03-02T00:00:00'}} |
CVE-2007-2768 | 2007-May | OpenSSH when using OPIE (One-Time Passwords in Everything) for PAM allows remote attackers to determine the existence of certain user accounts which displays a different response if the user account exists and is configured to use one-time passwords (OTP) a similar issue to CVE-2007-2243. | 0 | Moderate | 2026-02-18 01:21:20+03:00 | 2026-02-18 01:21:20+03:00 | Moderate | 91a8825ff65ab70cfe87b5fec01c11c847417a7238f83fabb6b101d587627192 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2007-May', 'vulnerability': {'CVE': 'CVE-2007-2768', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'OpenSSH when using OPIE (One-Time Passwords in Everything) for PAM allows remote attackers to determine the existence of certain user accounts which displays a different response if the user account exists and is configured to use one-time passwords (OTP) a similar issue to CVE-2007-2243.'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13372-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13373-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13374-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13375-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13376-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13377-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13378-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13379-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13380-12139'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13381-12139'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13382-12139'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13383-12139'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13384-12139'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13385-12140'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13386-12140'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13387-12140'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13388-12140'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13389-12140'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13390-12356'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13391-12356'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13392-12356'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13393-12356'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13394-12357'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13395-12357'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13396-12357'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['13397-12357'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19453-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13372-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13373-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13374-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13375-12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13376-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13377-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13378-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13379-12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13380-12139'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13381-12139'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13382-12139'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13383-12139'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13384-12139'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13385-12140'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13386-12140'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13387-12140'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13388-12140'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13389-12140'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13390-12356'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13391-12356'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13392-12356'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13393-12356'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13394-12357'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13395-12357'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13396-12357'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['13397-12357'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19453-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['13372-12137', '13373-12137', '13374-12137', '13375-12137', '13376-12138', '13377-12138', '13378-12138', '13379-12138', '13380-12139', '13381-12139', '13382-12139', '13384-12139', '13385-12140', '13386-12140', '13387-12140', '13389-12140', '13390-12356', '13391-12356', '13392-12356', '13394-12357', '13395-12357', '13396-12357'], 'FixedBuild': '-', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['13372-12137', '13373-12137', '13374-12137', '13375-12137', '13376-12138', '13377-12138', '13378-12138', '13379-12138', '13380-12139', '13381-12139', '13382-12139', '13384-12139', '13385-12140', '13386-12140', '13387-12140', '13389-12140', '13390-12356', '13391-12356', '13392-12356', '13394-12357', '13395-12357', '13396-12357'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['13383-12139', '13388-12140', '13393-12356', '13397-12357'], 'FixedBuild': '0.10.3-11', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['13383-12139', '13388-12140', '13393-12356', '13397-12357'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19453-17084'], 'FixedBuild': '9.5p1-2', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19453-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['13372-12137', '13373-12137', '13374-12137', '13375-12137', '13376-12138', '13377-12138', '13378-12138', '13379-12138', '13380-12139', '13381-12139', '13382-12139', '13383-12139', '13384-12139', '13385-12140', '13386-12140', '13387-12140', '13388-12140', '13389-12140', '13390-12356', '13391-12356', '13392-12356', '13393-12356', '13394-12357', '13395-12357', '13396-12357', '13397-12357', '19453-17084']}], 'RevisionHistory': [{'Date': '2026-02-18T01:21:20', 'Number': '1.3', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2021-12-16T00:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Added openssh to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-06-30T07:00:00', 'Number': '1.2', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2007-May'}, 'Alias': {'Value': '2007-May'}}, 'RevisionHistory': [{'Date': '2026-02-18T01:21:20', 'Number': '5', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T01:21:20', 'InitialReleaseDate': '2007-05-02T00:00:00'}} |
CVE-2008-0888 | 2008-Mar | The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data. | 0 | Critical | 2024-06-30 07:00:00+03:00 | 2020-09-25 00:00:00+03:00 | Critical | 503cc8dcb37b51f76327389ce7e25e9d5c1f845596c685e3e02d1f995fef0f52 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2008-Mar', 'vulnerability': {'CVE': 'CVE-2008-0888', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16921-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16845-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16846-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['18861-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16921-16820'], 'Description': {'Value': 'Critical'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16845-16823'], 'Description': {'Value': 'Critical'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16846-17084'], 'Description': {'Value': 'Critical'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['18861-17084'], 'Description': {}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16921-16820'], 'FixedBuild': '6.0-16', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16921-16820'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16845-16823'], 'FixedBuild': '6.0-19', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16845-16823'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16846-17084', '18861-17084'], 'FixedBuild': '6.0-20', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16846-17084', '18861-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16921-16820', '16845-16823', '16846-17084', '18861-17084']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2021-12-16T00:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Added unzip to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-06-30T07:00:00', 'Number': '1.2', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2008-Mar'}, 'Alias': {'Value': '2008-Mar'}}, 'RevisionHistory': [{'Date': '2024-06-30T07:00:00', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2024-06-30T07:00:00', 'InitialReleaseDate': '2008-03-02T00:00:00'}} |
CVE-2008-2149 | 2008-May | Stack-based buffer overflow in the searchwn function in Wordnet 2.0 2.1 and 3.0 might allow context-dependent attackers to execute arbitrary code via a long command line option. NOTE: this issue probably does not cross privilege boundaries except in cases in which Wordnet is used as a back end. | 0 | Important | 2024-06-30 07:00:00+03:00 | 2021-12-16 00:00:00+03:00 | Important | dc977a027e370b25962d630c30cffedfedc11f747e755e1d478e45ab8904a6b8 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2008-May', 'vulnerability': {'CVE': 'CVE-2008-2149', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Stack-based buffer overflow in the searchwn function in Wordnet 2.0 2.1 and 3.0 might allow context-dependent attackers to execute arbitrary code via a long command line option. NOTE: this issue probably does not cross privilege boundaries except in cases in which Wordnet is used as a back end.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19241-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19242-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19241-16823'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19242-17084'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19241-16823'], 'FixedBuild': '3.0-38', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19241-16823'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19242-17084'], 'FixedBuild': '3.0-43', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19242-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19241-16823', '19242-17084']}], 'RevisionHistory': [{'Date': '2021-12-16T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-06-30T07:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2008-May'}, 'Alias': {'Value': '2008-May'}}, 'RevisionHistory': [{'Date': '2024-06-30T07:00:00', 'Number': '2', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2024-06-30T07:00:00', 'InitialReleaseDate': '2008-05-02T00:00:00'}} |
CVE-2008-3912 | 2008-Sep | libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an out-of-memory condition. | 0 | Moderate | 2024-06-30 07:00:00+03:00 | 2020-10-25 00:00:00+03:00 | Moderate | 8a1c37f4cf849930076836d913f67323ec95c1d55d3c3578c1864cd814273341 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2008-Sep', 'vulnerability': {'CVE': 'CVE-2008-3912', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an out-of-memory condition.'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16999-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16999-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16999-16820'], 'FixedBuild': '0.103.2-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16999-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16999-16820']}], 'RevisionHistory': [{'Date': '2020-10-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2008-Sep'}, 'Alias': {'Value': '2008-Sep'}}, 'RevisionHistory': [{'Date': '2024-06-30T07:00:00', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2024-06-30T07:00:00', 'InitialReleaseDate': '2008-09-02T00:00:00'}} |
CVE-2008-3913 | 2008-Sep | Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic". | 0 | Moderate | 2024-06-30 07:00:00+03:00 | 2020-10-25 00:00:00+03:00 | Moderate | 983b9c75b6f12dcf2a25689344cbc4d057ec9756d7c86639cdbfaab71cbb252d | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2008-Sep', 'vulnerability': {'CVE': 'CVE-2008-3913', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic".'}, 'Ordinal': '2', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16999-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16999-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16999-16820'], 'FixedBuild': '0.103.2-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16999-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16999-16820']}], 'RevisionHistory': [{'Date': '2020-10-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2008-Sep'}, 'Alias': {'Value': '2008-Sep'}}, 'RevisionHistory': [{'Date': '2024-06-30T07:00:00', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2024-06-30T07:00:00', 'InitialReleaseDate': '2008-09-02T00:00:00'}} |
CVE-2008-3908 | 2008-Sep | Multiple buffer overflows in Princeton WordNet (wn) 3.0 allow context-dependent attackers to execute arbitrary code via (1) a long argument on the command line; a long (2) WNSEARCHDIR (3) WNHOME or (4) WNDBVERSION environment variable; or (5) a user-supplied dictionary (aka data file). NOTE: since WordNet itself does not run with special privileges this issue only crosses privilege boundaries when WordNet is invoked as a third party component. | 0 | Critical | 2024-06-30 07:00:00+03:00 | 2021-12-16 00:00:00+03:00 | Critical | 3bbf89a8cf40d568bfb339ee35e3ab29149739b45ba6d9ebb5b7e3583bd6e38c | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2008-Sep', 'vulnerability': {'CVE': 'CVE-2008-3908', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Multiple buffer overflows in Princeton WordNet (wn) 3.0 allow context-dependent attackers to execute arbitrary code via (1) a long argument on the command line; a long (2) WNSEARCHDIR (3) WNHOME or (4) WNDBVERSION environment variable; or (5) a user-supplied dictionary (aka data file). NOTE: since WordNet itself does not run with special privileges this issue only crosses privilege boundaries when WordNet is invoked as a third party component.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19241-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19242-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19241-16823'], 'Description': {'Value': 'Critical'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19242-17084'], 'Description': {'Value': 'Critical'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19241-16823'], 'FixedBuild': '3.0-38', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19241-16823'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19242-17084'], 'FixedBuild': '3.0-43', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19242-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19241-16823', '19242-17084']}], 'RevisionHistory': [{'Date': '2021-12-16T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-06-30T07:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2008-Sep'}, 'Alias': {'Value': '2008-Sep'}}, 'RevisionHistory': [{'Date': '2024-06-30T07:00:00', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2024-06-30T07:00:00', 'InitialReleaseDate': '2008-09-02T00:00:00'}} |
CVE-2008-3914 | 2008-Sep | Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c. | 0 | Critical | 2024-06-30 07:00:00+03:00 | 2020-10-25 00:00:00+03:00 | Critical | 33db70cf12de9a2ccec82a3268e37a4e994e5418f0c05e87544b0110a5479f9c | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2008-Sep', 'vulnerability': {'CVE': 'CVE-2008-3914', 'CWE': [{'ID': 'CWE-200', 'Value': 'Exposure of Sensitive Information to an Unauthorized Actor'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c.'}, 'Ordinal': '3', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16999-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16999-16820'], 'Description': {'Value': 'Critical'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16999-16820'], 'FixedBuild': '0.103.2-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16999-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16999-16820']}], 'RevisionHistory': [{'Date': '2020-10-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2008-Sep'}, 'Alias': {'Value': '2008-Sep'}}, 'RevisionHistory': [{'Date': '2024-06-30T07:00:00', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2024-06-30T07:00:00', 'InitialReleaseDate': '2008-09-02T00:00:00'}} |
CVE-2009-1241 | 2009-Apr | Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive. | 0 | Important | 2020-10-25 00:00:00+03:00 | 2020-10-25 00:00:00+03:00 | Important | b9d784dca18eca199a5dd948522355162463ff8f3cbed6e2586ce89e042d6d57 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2009-Apr', 'vulnerability': {'CVE': 'CVE-2009-1241', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16999-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16999-16820'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16999-16820'], 'FixedBuild': '0.103.2-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16999-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16999-16820']}], 'RevisionHistory': [{'Date': '2020-10-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2009-Apr'}, 'Alias': {'Value': '2009-Apr'}}, 'RevisionHistory': [{'Date': '2020-10-25T00:00:00', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2020-10-25T00:00:00', 'InitialReleaseDate': '2009-04-02T00:00:00'}} |
CVE-2009-4484 | 2009-Dec | Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9 as used in mysqld in MySQL 5.0.x before 5.0.90 MySQL 5.1.x before 5.1.43 MySQL 5.5.x through 5.5.0-m2 and other products allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a. | 0 | Important | 2020-09-25 00:00:00+03:00 | 2020-09-25 00:00:00+03:00 | Important | 4c0c1038d125dd29d94c3e49ad5e8d4566c7b4621fe2ec57c8aeb79c480c9f85 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2009-Dec', 'vulnerability': {'CVE': 'CVE-2009-4484', 'CWE': [{'ID': 'CWE-787', 'Value': 'Out-of-bounds Write'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9 as used in mysqld in MySQL 5.0.x before 5.0.90 MySQL 5.1.x before 5.1.43 MySQL 5.5.x through 5.5.0-m2 and other products allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16840-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16840-16820'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16840-16820'], 'FixedBuild': '-', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16840-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16840-16820']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2009-Dec'}, 'Alias': {'Value': '2009-Dec'}}, 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2020-09-25T00:00:00', 'InitialReleaseDate': '2009-12-02T00:00:00'}} |
CVE-2009-1890 | 2009-Jul | The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3 when a reverse proxy is configured does not properly handle an amount of streamed data that exceeds the Content-Length value which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests. | 0 | Important | 2022-05-27 00:00:00+03:00 | 2022-05-26 00:00:00+03:00 | Important | 321c1997ebb55daeb81164bfcfc1789ca168f7dc2e4458a1fe117d151b09a2e1 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2009-Jul', 'vulnerability': {'CVE': 'CVE-2009-1890', 'CWE': [{'ID': 'CWE-400', 'Value': 'Uncontrolled Resource Consumption'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3 when a reverse proxy is configured does not properly handle an amount of streamed data that exceeds the Content-Length value which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19243-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19244-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19243-16820'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19244-16823'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19243-16820', '19244-16823'], 'FixedBuild': '2.4.54-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19243-16820', '19244-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19243-16820', '19244-16823']}], 'RevisionHistory': [{'Date': '2022-05-26T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2022-05-27T00:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Added httpd to CBL-Mariner 2.0</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2009-Jul'}, 'Alias': {'Value': '2009-Jul'}}, 'RevisionHistory': [{'Date': '2022-05-27T00:00:00', 'Number': '2', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2022-05-27T00:00:00', 'InitialReleaseDate': '2009-07-02T00:00:00'}} |
CVE-2009-0590 | 2009-Mar | The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length. | 0 | Moderate | 2020-09-25 00:00:00+03:00 | 2020-09-25 00:00:00+03:00 | Moderate | ec62b5131fbb2ca10ed3c74268b97f455250a468184c31ab437985cb237a6cc6 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2009-Mar', 'vulnerability': {'CVE': 'CVE-2009-0590', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16878-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16878-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16878-16820'], 'FixedBuild': '-', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16878-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16878-16820']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2009-Mar'}, 'Alias': {'Value': '2009-Mar'}}, 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2020-09-25T00:00:00', 'InitialReleaseDate': '2009-03-02T00:00:00'}} |
CVE-2009-3767 | 2009-Oct | libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4 and possibly other versions when OpenSSL is used does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority a related issue to CVE-2009-2408. | 0 | Moderate | 2020-09-25 00:00:00+03:00 | 2020-09-25 00:00:00+03:00 | Moderate | e57556ab134ea4d1b44d6f7fc1aa784bb64b1ab62e73f5c9c5bf4e98fea4761b | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2009-Oct', 'vulnerability': {'CVE': 'CVE-2009-3767', 'CWE': [{'ID': 'CWE-295', 'Value': 'Improper Certificate Validation'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': "libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4 and possibly other versions when OpenSSL is used does not properly handle a '\\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority a related issue to CVE-2009-2408."}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16878-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16831-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16878-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16831-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16878-16820'], 'FixedBuild': '-', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16878-16820'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16831-16820'], 'FixedBuild': '2.4.57-2', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16831-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16878-16820', '16831-16820']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2009-Oct'}, 'Alias': {'Value': '2009-Oct'}}, 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2020-09-25T00:00:00', 'InitialReleaseDate': '2009-10-02T00:00:00'}} |
CVE-2010-2542 | 2010-Aug | Stack-based buffer overflow in the is_git_directory function in setup.c in Git before 1.7.2.1 allows local users to gain privileges via a long gitdir: field in a .git file in a working copy. | 0 | Important | 2020-09-25 00:00:00+03:00 | 2020-09-25 00:00:00+03:00 | Important | df7ad5d93b0bd5d0f2c4df9ac99b6eb326e3c9302e3effa258d66dc6d8e0b763 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2010-Aug', 'vulnerability': {'CVE': 'CVE-2010-2542', 'CWE': [{'ID': 'CWE-787', 'Value': 'Out-of-bounds Write'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Stack-based buffer overflow in the is_git_directory function in setup.c in Git before 1.7.2.1 allows local users to gain privileges via a long gitdir: field in a .git file in a working copy.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16924-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16924-16820'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16924-16820'], 'FixedBuild': '2.23.4-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16924-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16924-16820']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2010-Aug'}, 'Alias': {'Value': '2010-Aug'}}, 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2020-09-25T00:00:00', 'InitialReleaseDate': '2010-08-02T00:00:00'}} |
CVE-2010-0309 | 2010-Feb | The pit_ioport_read function in the Programmable Interval Timer (PIT) emulation in i8254.c in KVM 83 does not properly use the pit_state data structure which allows guest OS users to cause a denial of service (host OS crash or hang) by attempting to read the /dev/port file. | 0 | Moderate | 2026-02-19 01:07:42+03:00 | 2020-09-25 00:00:00+03:00 | Moderate | 5cb64edbd2197730d469e7bdb24e1b5befae992341207057ef40b55b915e2b21 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2010-Feb', 'vulnerability': {'CVE': 'CVE-2010-0309', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The pit_ioport_read function in the Programmable Interval Timer (PIT) emulation in i8254.c in KVM 83 does not properly use the pit_state data structure which allows guest OS users to cause a denial of service (host OS crash or hang) by attempting to read the /dev/port file.'}, 'Ordinal': '2', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16919-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16920-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17065-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19529-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16919-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16920-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17065-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19529-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16919-16820'], 'FixedBuild': '-', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16919-16820'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16920-16823'], 'FixedBuild': '5.10.78.1-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16920-16823'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['17065-17084', '19529-17084'], 'FixedBuild': '6.6.35.1-4', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['17065-17084', '19529-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16919-16820', '16920-16823', '17065-17084', '19529-17084']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2021-12-16T00:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Added kernel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-08-15T00:00:00', 'Number': '1.2', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2026-02-19T01:07:06', 'Number': '1.3', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2010-Feb'}, 'Alias': {'Value': '2010-Feb'}}, 'RevisionHistory': [{'Date': '2026-02-19T01:07:42', 'Number': '7', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-19T01:07:42', 'InitialReleaseDate': '2010-02-02T00:00:00'}} |
CVE-2010-0298 | 2010-Feb | The x86 emulator in KVM 83 does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) in determining the memory access available to CPL3 code which allows guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region a related issue to CVE-2010-0306. | 0 | Moderate | 2026-02-19 01:07:42+03:00 | 2026-02-19 01:07:42+03:00 | Moderate | d8359843a02799a37b177c2783b8a5f4e5943d8d789cd2ed836d09b2fbc8823d | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2010-Feb', 'vulnerability': {'CVE': 'CVE-2010-0298', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The x86 emulator in KVM 83 does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) in determining the memory access available to CPL3 code which allows guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region a related issue to CVE-2010-0306.'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16919-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16920-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17675-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19709-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16919-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16920-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17675-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19709-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16919-16820'], 'FixedBuild': '-', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16919-16820'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16920-16823'], 'FixedBuild': '5.10.78.1-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16920-16823'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['17675-17084', '19709-17084'], 'FixedBuild': '6.6.35.1-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['17675-17084', '19709-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16919-16820', '16920-16823', '17675-17084', '19709-17084']}], 'RevisionHistory': [{'Date': '2026-02-19T01:07:42', 'Number': '1.3', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2021-12-16T00:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Added kernel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-08-15T00:00:00', 'Number': '1.2', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2010-Feb'}, 'Alias': {'Value': '2010-Feb'}}, 'RevisionHistory': [{'Date': '2026-02-19T01:07:42', 'Number': '7', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-19T01:07:42', 'InitialReleaseDate': '2010-02-02T00:00:00'}} |
CVE-2010-0291 | 2010-Feb | The Linux kernel before 2.6.32.4 allows local users to gain privileges or cause a denial of service (panic) by calling the (1) mmap or (2) mremap function, aka the "do_mremap() mess" or "mremap/mmap mess." | 0 | Moderate | 2026-02-19 01:07:42+03:00 | 2026-02-18 03:04:10+03:00 | Moderate | dc44a2702c8db425b78071995337c0ee955ba4435ac76e5f36b652804e5505f8 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2010-Feb', 'vulnerability': {'CVE': 'CVE-2010-0291', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The Linux kernel before 2.6.32.4 allows local users to gain privileges or cause a denial of service (panic) by calling the (1) mmap or (2) mremap function, aka the "do_mremap() mess" or "mremap/mmap mess."'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17459-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17459-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['17459-17084']}], 'RevisionHistory': [{'Date': '2026-02-18T03:04:10', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2025-09-03T22:00:06', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2010-Feb'}, 'Alias': {'Value': '2010-Feb'}}, 'RevisionHistory': [{'Date': '2026-02-19T01:07:42', 'Number': '7', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-19T01:07:42', 'InitialReleaseDate': '2010-02-02T00:00:00'}} |
CVE-2009-4487 | 2010-Jan | nginx 0.7.64 writes data to a log file without sanitizing non-printable characters which might allow remote attackers to modify a window's title or possibly execute arbitrary commands or overwrite files via an HTTP request containing an escape sequence for a terminal emulator. | 0 | Moderate | 2020-11-17 00:00:00+03:00 | 2020-11-17 00:00:00+03:00 | Moderate | faaae3b674b11fb43a4999ff280c747d0179bb1ba8499c805d0fd5bfcc73f2f7 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2010-Jan', 'vulnerability': {'CVE': 'CVE-2009-4487', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': "nginx 0.7.64 writes data to a log file without sanitizing non-printable characters which might allow remote attackers to modify a window's title or possibly execute arbitrary commands or overwrite files via an HTTP request containing an escape sequence for a terminal emulator."}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17046-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17046-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['17046-16820'], 'FixedBuild': '1.16.1-4', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['17046-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['17046-16820']}], 'RevisionHistory': [{'Date': '2020-11-17T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2010-Jan'}, 'Alias': {'Value': '2010-Jan'}}, 'RevisionHistory': [{'Date': '2020-11-17T00:00:00', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2020-11-17T00:00:00', 'InitialReleaseDate': '2010-01-02T00:00:00'}} |
CVE-2022-40898 | 2024-Oct | 0 | 2026-05-17 14:47:42+03:00 | 2024-09-26 00:00:00+03:00 | 53207a604d995f276f2088ba2343f9a61ea4f3d26795f5a89d2df9023ac4accb | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2024-Oct', 'vulnerability': {'CVE': 'CVE-2022-40898', 'Notes': [{'Type': 6, 'Title': 'NIST NVD Details', 'Value': 'https://nvd.nist.gov/vuln/detail/CVE-2022-40898', 'Ordinal': '1'}, {'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'cve@mitre.org', 'Value': 'cve@mitre.org', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {}, 'Ordinal': '46', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['12356'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['12357'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['12139'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['12140'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['12356'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['12357'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['12139'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['12140'], 'Description': {}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'CBL-Mariner', 'ProductID': ['12139', '12140'], 'FixedBuild': '0.33.6-8', 'Description': {'Value': 'python-wheel'}, 'AffectedFiles': [{'FileName': 'python3-wheel-0.33.6-8.cm2.noarch.rpm', 'FileLastModified': '0001-01-01T00:00:00'}, {'FileName': 'python-wheel-wheel-0.33.6-8.cm2.noarch.rpm', 'FileLastModified': '0001-01-01T00:00:00'}], 'DateSpecified': False, 'RestartRequired': {}}, {'URL': 'https://nvd.nist.gov/vuln/detail/CVE-2022-40898', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'python-wheel', 'ProductID': ['12139', '12140'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [{'Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'BaseScore': 7.5, 'ProductID': ['12356'], 'TemporalScore': 7.5, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'BaseScore': 7.5, 'ProductID': ['12357'], 'TemporalScore': 7.5, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'BaseScore': 7.5, 'ProductID': ['12139'], 'TemporalScore': 7.5, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'BaseScore': 7.5, 'ProductID': ['12140'], 'TemporalScore': 7.5, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['12356', '12357', '12139', '12140']}], 'RevisionHistory': [{'Date': '2024-09-26T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-28T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-29T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-30T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-01T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-02T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-03T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-09T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-15T00:00:00', 'Number': '2.0', 'Description': {'Value': '<p>Added python-wheel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-10-17T00:00:00', 'Number': '4.0', 'Description': {'Value': '<p>Added python-wheel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-10-20T00:00:00', 'Number': '7.0', 'Description': {'Value': '<p>Added python-wheel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-10-24T00:00:00', 'Number': '11.0', 'Description': {'Value': '<p>Added python-wheel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-10-26T00:00:00', 'Number': '13.0', 'Description': {'Value': '<p>Added python-wheel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-10-28T00:00:00', 'Number': '15.0', 'Description': {'Value': '<p>Added python-wheel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-10-29T00:00:00', 'Number': '16.0', 'Description': {'Value': '<p>Added python-wheel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-10-30T00:00:00', 'Number': '17.0', 'Description': {'Value': '<p>Added python-wheel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-09-13T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-14T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-15T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-16T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-17T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-18T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-19T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-20T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-21T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-22T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-23T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-24T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-27T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-04T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-05T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-06T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-07T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-10T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-11T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-12T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-13T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-14T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-16T00:00:00', 'Number': '3.0', 'Description': {'Value': '<p>Added python-wheel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-10-18T00:00:00', 'Number': '5.0', 'Description': {'Value': '<p>Added python-wheel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-10-19T00:00:00', 'Number': '6.0', 'Description': {'Value': '<p>Added python-wheel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-10-21T00:00:00', 'Number': '8.0', 'Description': {'Value': '<p>Added python-wheel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-10-22T00:00:00', 'Number': '9.0', 'Description': {'Value': '<p>Added python-wheel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-10-23T00:00:00', 'Number': '10.0', 'Description': {'Value': '<p>Added python-wheel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-10-25T00:00:00', 'Number': '12.0', 'Description': {'Value': '<p>Added python-wheel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-10-27T00:00:00', 'Number': '14.0', 'Description': {'Value': '<p>Added python-wheel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-10-31T00:00:00', 'Number': '18.0', 'Description': {'Value': '<p>Added python-wheel to CBL-Mariner 2.0</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2024-Oct'}, 'Alias': {'Value': '2024-Oct'}}, 'RevisionHistory': [{'Date': '2026-05-17T14:47:42', 'Number': '630', 'Description': {'Value': 'October 2024 Security Updates'}}], 'CurrentReleaseDate': '2026-05-17T14:47:42', 'InitialReleaseDate': '2024-10-08T07:00:00'}} | |||
CVE-2010-2249 | 2010-Jun | Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks. | 0 | Moderate | 2025-09-03 23:15:39+03:00 | 2025-09-03 23:15:39+03:00 | Moderate | 386eaaf85ff7bce715b413a6203689eeb9d3fa025eee951f6247862ed4084ece | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2010-Jun', 'vulnerability': {'CVE': 'CVE-2010-2249', 'CWE': [{'ID': 'CWE-401', 'Value': 'Missing Release of Memory after Effective Lifetime'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19237-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16848-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19237-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16848-17084'], 'Description': {}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19237-17084'], 'FixedBuild': 'libpng-1.2.44', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19237-17084'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16848-17084'], 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16848-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [{'Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'BaseScore': 6.5, 'ProductID': ['19237-17084'], 'TemporalScore': 6.5, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'BaseScore': 6.5, 'ProductID': ['16848-17084'], 'TemporalScore': 6.5, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19237-17084', '16848-17084']}], 'RevisionHistory': [{'Date': '2025-09-03T23:15:39', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2010-Jun'}, 'Alias': {'Value': '2010-Jun'}}, 'RevisionHistory': [{'Date': '2025-09-03T23:15:39', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-09-03T23:15:39', 'InitialReleaseDate': '2010-06-02T00:00:00'}} |
CVE-2010-2891 | 2010-Oct | Buffer overflow in the smiGetNode function in lib/smi.c in libsmi 0.4.8 allows context-dependent attackers to execute arbitrary code via an Object Identifier (aka OID) represented as a numerical string containing many components separated by . (dot) characters. | 0 | Important | 2026-02-19 01:18:21+03:00 | 2021-12-16 00:00:00+03:00 | Important | 82c91b43e66c559d83df03a84cf6893c5bf8dbc07dd4d6aace7f0dbb2434958d | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2010-Oct', 'vulnerability': {'CVE': 'CVE-2010-2891', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Buffer overflow in the smiGetNode function in lib/smi.c in libsmi 0.4.8 allows context-dependent attackers to execute arbitrary code via an Object Identifier (aka OID) represented as a numerical string containing many components separated by . (dot) characters.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19229-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19230-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['20060-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19229-16823'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19230-17084'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['20060-17084'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19229-16823'], 'FixedBuild': '0.4.8-27', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19229-16823'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19230-17084', '20060-17084'], 'FixedBuild': '0.4.8-28', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19230-17084', '20060-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19229-16823', '19230-17084', '20060-17084']}], 'RevisionHistory': [{'Date': '2021-12-16T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-06-30T07:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2026-02-19T01:18:21', 'Number': '1.2', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2010-Oct'}, 'Alias': {'Value': '2010-Oct'}}, 'RevisionHistory': [{'Date': '2026-02-19T01:18:21', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-19T01:18:21', 'InitialReleaseDate': '2010-10-02T00:00:00'}} |
CVE-2009-5063 | 2011-Aug | Memory leak in the embedded_profile_len function in pngwutil.c in libpng before 1.2.39beta5 allows context-dependent attackers to cause a denial of service (memory leak or segmentation fault) via a JPEG image containing an iCCP chunk with a negative embedded profile length. NOTE: this is due to an incomplete fix for CVE-2006-7244. | 0 | Moderate | 2026-02-18 14:28:28+03:00 | 2025-09-03 20:45:49+03:00 | Moderate | 3cc999c55177ff593f017b3c2134f31423fb92ed40f496b47ce2e3b01a87d90b | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2011-Aug', 'vulnerability': {'CVE': 'CVE-2009-5063', 'CWE': [{'ID': 'CWE-401', 'Value': 'Missing Release of Memory after Effective Lifetime'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Memory leak in the embedded_profile_len function in pngwutil.c in libpng before 1.2.39beta5 allows context-dependent attackers to cause a denial of service (memory leak or segmentation fault) via a JPEG image containing an iCCP chunk with a negative embedded profile length. NOTE: this is due to an incomplete fix for CVE-2006-7244.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19245-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16848-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19245-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16848-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19245-17084'], 'FixedBuild': 'libpng-1.2.39', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19245-17084'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16848-17084'], 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16848-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19245-17084', '16848-17084']}], 'RevisionHistory': [{'Date': '2025-09-03T20:45:49', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2026-02-18T14:28:28', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2011-Aug'}, 'Alias': {'Value': '2011-Aug'}}, 'RevisionHistory': [{'Date': '2026-02-18T14:28:28', 'Number': '2', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T14:28:28', 'InitialReleaseDate': '2011-08-02T00:00:00'}} |
CVE-2010-3865 | 2011-Jan | Integer overflow in the rds_rdma_pages function in net/rds/rdma.c in the Linux kernel allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted iovec struct in a Reliable Datagram Sockets (RDS) request which triggers a buffer overflow. | 0 | Important | 2025-10-01 23:10:51+03:00 | 2020-09-25 00:00:00+03:00 | Important | 7f1564383fbec2abd42e31a71d0abfcc11820caf8993d7c1305b1d464b8550cc | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2011-Jan', 'vulnerability': {'CVE': 'CVE-2010-3865', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Integer overflow in the rds_rdma_pages function in net/rds/rdma.c in the Linux kernel allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted iovec struct in a Reliable Datagram Sockets (RDS) request which triggers a buffer overflow.'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19217-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19217-16820'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19217-16820'], 'FixedBuild': '5.4.72-11', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19217-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19217-16820']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2011-Jan'}, 'Alias': {'Value': '2011-Jan'}}, 'RevisionHistory': [{'Date': '2025-10-01T23:10:51', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-10-01T23:10:51', 'InitialReleaseDate': '2011-01-02T00:00:00'}} |
CVE-2010-2642 | 2011-Jan | Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other products allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer. | 0 | Important | 2025-10-01 23:10:51+03:00 | 2025-10-01 23:10:51+03:00 | Important | 1976d33f4a6419183d07c4f51f960e6c713eb4db769a10521d8d1d8db0d2d54d | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2011-Jan', 'vulnerability': {'CVE': 'CVE-2010-2642', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other products allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19227-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19227-16823'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19227-16823'], 'FixedBuild': '5.1.2-28', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19227-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19227-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:51', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2011-Jan'}, 'Alias': {'Value': '2011-Jan'}}, 'RevisionHistory': [{'Date': '2025-10-01T23:10:51', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-10-01T23:10:51', 'InitialReleaseDate': '2011-01-02T00:00:00'}} |
CVE-2011-0640 | 2011-Jan | The default configuration of udev on Linux does not warn the user before enabling additional Human Interface Device (HID) functionality over USB which allows user-assisted attackers to execute arbitrary programs via crafted USB data as demonstrated by keyboard and mouse data sent by malware on a smartphone that the user connected to the computer. | 0 | Moderate | 2025-10-01 23:10:51+03:00 | 2020-09-25 00:00:00+03:00 | Moderate | 79f4cb97ef64b023846c298d362615705b2c8d861aac360d9e317429f0979b55 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2011-Jan', 'vulnerability': {'CVE': 'CVE-2011-0640', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The default configuration of udev on Linux does not warn the user before enabling additional Human Interface Device (HID) functionality over USB which allows user-assisted attackers to execute arbitrary programs via crafted USB data as demonstrated by keyboard and mouse data sent by malware on a smartphone that the user connected to the computer.'}, 'Ordinal': '2', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16919-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16920-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16919-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16920-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16919-16820'], 'FixedBuild': '-', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16919-16820'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16920-16823'], 'FixedBuild': '5.10.78.1-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16920-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16919-16820', '16920-16823']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2021-12-16T00:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Added kernel to CBL-Mariner 2.0</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2011-Jan'}, 'Alias': {'Value': '2011-Jan'}}, 'RevisionHistory': [{'Date': '2025-10-01T23:10:51', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-10-01T23:10:51', 'InitialReleaseDate': '2011-01-02T00:00:00'}} |
CVE-2011-2501 | 2011-Jul | The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers an out-of-bounds read during the copying of error-message data. NOTE: this vulnerability exists because of a CVE-2004-0421 regression. NOTE: this is called an off-by-one error by some sources. | 0 | Moderate | 2025-04-16 00:00:00+03:00 | 2025-04-16 00:00:00+03:00 | Moderate | 27543d4b01506a0f6b32d83fb6c75da3af7fb1761ca303dcf3db6372653d5d8d | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2011-Jul', 'vulnerability': {'CVE': 'CVE-2011-2501', 'CWE': [{'ID': 'CWE-125', 'Value': 'Out-of-bounds Read'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers an out-of-bounds read during the copying of error-message data. NOTE: this vulnerability exists because of a CVE-2004-0421 regression. NOTE: this is called an off-by-one error by some sources.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16848-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16848-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16848-17084'], 'FixedBuild': '6.04-11', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16848-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [{'Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'BaseScore': 6.5, 'ProductID': ['16848-17084'], 'TemporalScore': 6.5, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16848-17084']}], 'RevisionHistory': [{'Date': '2025-04-16T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2011-Jul'}, 'Alias': {'Value': '2011-Jul'}}, 'RevisionHistory': [{'Date': '2025-04-16T00:00:00', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-04-16T00:00:00', 'InitialReleaseDate': '2011-07-02T00:00:00'}} |
CVE-2011-2691 | 2011-Jul | The png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 makes a function call using a NULL pointer argument instead of an empty-string argument, which allows remote attackers to cause a denial of service (application crash) via a crafted PNG image. | 0 | Moderate | 2025-04-16 00:00:00+03:00 | 2025-04-16 00:00:00+03:00 | Moderate | c368b9fca653fd37d6d1b5f11ef3cbab47e3a137e62f8287cca31be543d9fab0 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2011-Jul', 'vulnerability': {'CVE': 'CVE-2011-2691', 'CWE': [{'ID': 'CWE-476', 'Value': 'NULL Pointer Dereference'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 makes a function call using a NULL pointer argument instead of an empty-string argument, which allows remote attackers to cause a denial of service (application crash) via a crafted PNG image.'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16848-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16848-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16848-17084'], 'FixedBuild': '6.04-11', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16848-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [{'Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'BaseScore': 6.5, 'ProductID': ['16848-17084'], 'TemporalScore': 6.5, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16848-17084']}], 'RevisionHistory': [{'Date': '2025-04-16T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2011-Jul'}, 'Alias': {'Value': '2011-Jul'}}, 'RevisionHistory': [{'Date': '2025-04-16T00:00:00', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-04-16T00:00:00', 'InitialReleaseDate': '2011-07-02T00:00:00'}} |
CVE-2010-4756 | 2011-Mar | The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632. | 0 | Moderate | 2026-02-18 03:09:43+03:00 | 2025-09-04 04:29:41+03:00 | Moderate | 6eda35339faa0a5ab12f3190b23891388c3c8e1529907cd76631ba404cc750dd | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2011-Mar', 'vulnerability': {'CVE': 'CVE-2010-4756', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17077-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17348-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19758-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['20249-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['20250-17086'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17077-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17348-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19758-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['20249-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['20250-17086'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['17077-16820'], 'FixedBuild': '2.28-24', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['17077-16820'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['17348-16823'], 'FixedBuild': '2.35-7', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['17348-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['17077-16820', '17348-16823', '19758-17084', '20249-17084', '20250-17086']}], 'RevisionHistory': [{'Date': '2025-09-04T04:29:41', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2026-02-18T03:09:43', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2011-Mar'}, 'Alias': {'Value': '2011-Mar'}}, 'RevisionHistory': [{'Date': '2026-02-18T03:09:43', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T03:09:43', 'InitialReleaseDate': '2011-03-02T00:00:00'}} |
CVE-2011-1429 | 2011-Mar | Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766. | 0 | Moderate | 2026-02-18 03:09:43+03:00 | 2025-10-01 23:10:51+03:00 | Moderate | 138517be8e09fa64c9616dbb7fb4e1711af9acdfe2bb766f07657578e3080a40 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2011-Mar', 'vulnerability': {'CVE': 'CVE-2011-1429', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['18316-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['18316-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['18316-16823'], 'FixedBuild': '2.2.12-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['18316-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['18316-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:51', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2011-Mar'}, 'Alias': {'Value': '2011-Mar'}}, 'RevisionHistory': [{'Date': '2026-02-18T03:09:43', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T03:09:43', 'InitialReleaseDate': '2011-03-02T00:00:00'}} |
CVE-2012-0883 | 2012-Apr | envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl. | 0 | Moderate | 2026-02-18 14:23:14+03:00 | 2026-02-18 14:23:14+03:00 | Moderate | 9234d764f9be30ed03bd3ad3aa4afb0faf9e15866cf5357cbeb6c4ed8a7e7a87 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2012-Apr', 'vulnerability': {'CVE': 'CVE-2012-0883', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19236-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17686-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19236-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17686-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19236-17084'], 'FixedBuild': 'httpd-2.4.2', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19236-17084'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['17686-17084'], 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['17686-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19236-17084', '17686-17084']}], 'RevisionHistory': [{'Date': '2026-02-18T14:23:14', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2025-09-03T20:26:28', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2012-Apr'}, 'Alias': {'Value': '2012-Apr'}}, 'RevisionHistory': [{'Date': '2026-02-18T14:23:14', 'Number': '2', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T14:23:14', 'InitialReleaseDate': '2012-04-02T00:00:00'}} |
CVE-2012-3425 | 2012-Aug | The png_push_read_zTXt function allows remote attackers to cause a denial of service | 0 | Moderate | 2025-10-01 23:10:53+03:00 | 2025-04-16 00:00:00+03:00 | Moderate | e14edf785f09b70fd1ee530e27f9728f087710117d3a6ab58dc7df61cf276ddf | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2012-Aug', 'vulnerability': {'CVE': 'CVE-2012-3425', 'CWE': [{'ID': 'CWE-119', 'Value': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The png_push_read_zTXt function allows remote attackers to cause a denial of service'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16848-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16848-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16848-17084'], 'FixedBuild': '6.04-11', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16848-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16848-17084']}], 'RevisionHistory': [{'Date': '2025-04-16T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2012-Aug'}, 'Alias': {'Value': '2012-Aug'}}, 'RevisionHistory': [{'Date': '2025-10-01T23:10:53', 'Number': '2', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-10-01T23:10:53', 'InitialReleaseDate': '2012-08-02T00:00:00'}} |
CVE-2012-3381 | 2012-Aug | sfcb in sblim-sfcb places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | 0 | Moderate | 2025-10-01 23:10:53+03:00 | 2025-10-01 23:10:53+03:00 | Moderate | dae1340aeeb5e73fd80b1b38bad7f1b3703282ab3ed948c5e06c239ce46180a8 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2012-Aug', 'vulnerability': {'CVE': 'CVE-2012-3381', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'sfcb in sblim-sfcb places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19228-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19228-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19228-16823'], 'FixedBuild': '1.4.9-20', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19228-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19228-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:53', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2012-Aug'}, 'Alias': {'Value': '2012-Aug'}}, 'RevisionHistory': [{'Date': '2025-10-01T23:10:53', 'Number': '2', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-10-01T23:10:53', 'InitialReleaseDate': '2012-08-02T00:00:00'}} |
CVE-2010-4563 | 2012-Feb | The Linux kernel when using IPv6 allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent as demonstrated by thcping. | 0 | Moderate | 2026-02-19 01:07:54+03:00 | 2026-02-19 01:07:54+03:00 | Moderate | f31e8ee7776d5c7778840a6a08b5456da0e87060892bccf9f66d5383caad0695 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2012-Feb', 'vulnerability': {'CVE': 'CVE-2010-4563', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The Linux kernel when using IPv6 allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent as demonstrated by thcping.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16919-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16920-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17065-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19529-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16919-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16920-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17065-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19529-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16919-16820'], 'FixedBuild': '-', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16919-16820'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16920-16823'], 'FixedBuild': '5.10.78.1-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16920-16823'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['17065-17084', '19529-17084'], 'FixedBuild': '6.6.35.1-4', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['17065-17084', '19529-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16919-16820', '16920-16823', '17065-17084', '19529-17084']}], 'RevisionHistory': [{'Date': '2026-02-19T01:07:54', 'Number': '1.3', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2021-12-16T00:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Added kernel to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-08-15T00:00:00', 'Number': '1.2', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2012-Feb'}, 'Alias': {'Value': '2012-Feb'}}, 'RevisionHistory': [{'Date': '2026-02-19T01:07:54', 'Number': '4', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-19T01:07:54', 'InitialReleaseDate': '2012-02-02T00:00:00'}} |
CVE-2012-2677 | 2012-Jul | Integer overflow in the ordered_malloc function in boost/pool/pool.hpp in Boost Pool | 0 | Moderate | 2026-02-18 01:26:35+03:00 | 2024-12-07 00:00:00+03:00 | Moderate | 6ac4bd645fc3fd3b25fd32f9bfdf8005dc0bec43415ee3b1655f3ba31488fbc1 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2012-Jul', 'vulnerability': {'CVE': 'CVE-2012-2677', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Integer overflow in the ordered_malloc function in boost/pool/pool.hpp in Boost Pool'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16855-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19234-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17539-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19666-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16855-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19234-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17539-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19666-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16855-17084', '19666-17084'], 'FixedBuild': '18.2.2-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16855-17084', '19666-17084'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19234-17084', '17539-17084'], 'FixedBuild': '8.0.40-4', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19234-17084', '17539-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16855-17084', '19234-17084', '17539-17084', '19666-17084']}], 'RevisionHistory': [{'Date': '2024-12-07T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2025-02-27T00:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-02-28T00:00:00', 'Number': '1.2', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-03T00:00:00', 'Number': '1.5', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-05T00:00:00', 'Number': '1.7', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-06T00:00:00', 'Number': '1.8', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-08T00:00:00', 'Number': '1.9', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-12T00:00:00', 'Number': '2.3', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-21T00:00:00', 'Number': '3.2', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-23T00:00:00', 'Number': '3.4', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-27T00:00:00', 'Number': '3.8', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-28T00:00:00', 'Number': '3.9', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-31T00:00:00', 'Number': '4.2', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-01T00:00:00', 'Number': '4.3', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-04T00:00:00', 'Number': '4.5', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-05T00:00:00', 'Number': '4.6', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-07T00:00:00', 'Number': '4.8', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-08T00:00:00', 'Number': '4.9', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-13T00:00:00', 'Number': '5.3', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-16T00:00:00', 'Number': '5.6', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-17T00:00:00', 'Number': '5.7', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-18T00:00:00', 'Number': '5.8', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-20T00:00:00', 'Number': '6.0', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-22T00:00:00', 'Number': '6.2', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-28T00:00:00', 'Number': '6.7', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-30T00:00:00', 'Number': '6.9', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-03T00:00:00', 'Number': '7.2', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-04T00:00:00', 'Number': '7.3', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-05T00:00:00', 'Number': '7.4', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-06T00:00:00', 'Number': '7.5', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-07T00:00:00', 'Number': '7.6', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-10T00:00:00', 'Number': '7.9', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-11T00:00:00', 'Number': '8.0', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-14T00:00:00', 'Number': '8.3', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-15T00:00:00', 'Number': '8.4', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-19T00:00:00', 'Number': '8.8', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-20T00:00:00', 'Number': '8.9', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-21T00:00:00', 'Number': '9.0', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-25T00:00:00', 'Number': '9.4', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-26T00:00:00', 'Number': '9.5', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-01T00:00:00', 'Number': '1.3', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-02T00:00:00', 'Number': '1.4', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-04T00:00:00', 'Number': '1.6', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-09T00:00:00', 'Number': '2.0', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-10T00:00:00', 'Number': '2.1', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-11T00:00:00', 'Number': '2.2', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-13T00:00:00', 'Number': '2.4', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-14T00:00:00', 'Number': '2.5', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-15T00:00:00', 'Number': '2.6', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-16T00:00:00', 'Number': '2.7', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-17T00:00:00', 'Number': '2.8', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-18T00:00:00', 'Number': '2.9', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-19T00:00:00', 'Number': '3.0', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-20T00:00:00', 'Number': '3.1', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-22T00:00:00', 'Number': '3.3', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-24T00:00:00', 'Number': '3.5', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-25T00:00:00', 'Number': '3.6', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-26T00:00:00', 'Number': '3.7', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-29T00:00:00', 'Number': '4.0', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-03-30T00:00:00', 'Number': '4.1', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-03T00:00:00', 'Number': '4.4', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-06T00:00:00', 'Number': '4.7', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-09T00:00:00', 'Number': '5.0', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-11T00:00:00', 'Number': '5.1', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-12T00:00:00', 'Number': '5.2', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-14T00:00:00', 'Number': '5.4', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-15T00:00:00', 'Number': '5.5', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-19T00:00:00', 'Number': '5.9', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-21T00:00:00', 'Number': '6.1', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-23T00:00:00', 'Number': '6.3', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-24T00:00:00', 'Number': '6.4', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-25T00:00:00', 'Number': '6.5', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-26T00:00:00', 'Number': '6.6', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-29T00:00:00', 'Number': '6.8', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-01T00:00:00', 'Number': '7.0', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-02T00:00:00', 'Number': '7.1', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-08T00:00:00', 'Number': '7.7', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-09T00:00:00', 'Number': '7.8', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-12T00:00:00', 'Number': '8.1', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-13T00:00:00', 'Number': '8.2', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-16T00:00:00', 'Number': '8.5', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-17T00:00:00', 'Number': '8.6', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-18T00:00:00', 'Number': '8.7', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-22T00:00:00', 'Number': '9.1', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-23T00:00:00', 'Number': '9.2', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-24T00:00:00', 'Number': '9.3', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2025-05-27T00:00:00', 'Number': '9.6', 'Description': {'Value': '<p>Added mysql to Azure Linux 3.0</p>\n'}}, {'Date': '2026-02-18T01:26:35', 'Number': '9.7', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2012-Jul'}, 'Alias': {'Value': '2012-Jul'}}, 'RevisionHistory': [{'Date': '2026-02-18T01:26:35', 'Number': '89', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T01:26:35', 'InitialReleaseDate': '2012-07-02T00:00:00'}} |
CVE-2012-2653 | 2012-Jul | arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root privileges by leveraging other vulnerabilities in the daemon. | 0 | Critical | 2026-02-18 01:26:35+03:00 | 2025-10-01 23:10:52+03:00 | Critical | cb660b8902a3a20c96b070b71f3f7ff4dfd4cd2db1d7cdb27fdf209058228a39 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2012-Jul', 'vulnerability': {'CVE': 'CVE-2012-2653', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root privileges by leveraging other vulnerabilities in the daemon.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19232-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19232-16823'], 'Description': {'Value': 'Critical'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19232-16823'], 'FixedBuild': '2.1a15-51', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19232-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19232-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:52', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2012-Jul'}, 'Alias': {'Value': '2012-Jul'}}, 'RevisionHistory': [{'Date': '2026-02-18T01:26:35', 'Number': '89', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T01:26:35', 'InitialReleaseDate': '2012-07-02T00:00:00'}} |
CVE-2011-3045 | 2012-Mar | Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026. | 0 | Moderate | 2025-06-13 00:00:00+03:00 | 2025-06-13 00:00:00+03:00 | Moderate | ea03fc444230084c95a3d9a855fdfb45f63ca97f7bfc20ab11ab10d6b3c5c0ac | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2012-Mar', 'vulnerability': {'CVE': 'CVE-2011-3045', 'CWE': [{'ID': 'CWE-190', 'Value': 'Integer Overflow or Wraparound'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16848-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16848-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16848-17084'], 'FixedBuild': '6.04-11', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16848-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [{'Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H', 'BaseScore': 8.8, 'ProductID': ['16848-17084'], 'TemporalScore': 8.8, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16848-17084']}], 'RevisionHistory': [{'Date': '2025-06-13T00:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Added syslinux to Azure Linux 3.0</p>\n'}}, {'Date': '2025-04-16T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2012-Mar'}, 'Alias': {'Value': '2012-Mar'}}, 'RevisionHistory': [{'Date': '2025-06-13T00:00:00', 'Number': '2', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-06-13T00:00:00', 'InitialReleaseDate': '2012-03-02T00:00:00'}} |
CVE-2011-3048 | 2012-May | The png_set_text_2 function in pngset.c in libpng 1.0.x before 1.0.59, 1.2.x before 1.2.49, 1.4.x before 1.4.11, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted text chunk in a PNG image file, which triggers a memory allocation failure that is not properly handled, leading to a heap-based buffer overflow. | 0 | Moderate | 2026-02-18 14:43:57+03:00 | 2025-09-03 22:14:56+03:00 | Moderate | 7e1355d7194cabc0208d4045e1c3d506b88ef4f90a678723c6b9f8d06ce8d0b3 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2012-May', 'vulnerability': {'CVE': 'CVE-2011-3048', 'CWE': [{'ID': 'CWE-119', 'Value': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The png_set_text_2 function in pngset.c in libpng 1.0.x before 1.0.59, 1.2.x before 1.2.49, 1.4.x before 1.4.11, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted text chunk in a PNG image file, which triggers a memory allocation failure that is not properly handled, leading to a heap-based buffer overflow.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16848-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16848-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16848-17084']}], 'RevisionHistory': [{'Date': '2025-09-03T22:14:56', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2026-02-18T14:43:57', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2012-May'}, 'Alias': {'Value': '2012-May'}}, 'RevisionHistory': [{'Date': '2026-02-18T14:43:57', 'Number': '2', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T14:43:57', 'InitialReleaseDate': '2012-05-02T00:00:00'}} |
CVE-2011-0433 | 2012-Nov | Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, a different vulnerability than CVE-2010-2642. | 0 | Moderate | 2025-10-01 23:10:52+03:00 | 2025-10-01 23:10:51+03:00 | Moderate | f5404adbfdbd149cba8f4e77b66bbb5d3438b8256864edc19f6213de64740953 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2012-Nov', 'vulnerability': {'CVE': 'CVE-2011-0433', 'CWE': [{'ID': 'CWE-119', 'Value': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, a different vulnerability than CVE-2010-2642.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19227-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19227-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19227-16823'], 'FixedBuild': '5.1.2-28', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19227-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19227-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:51', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2012-Nov'}, 'Alias': {'Value': '2012-Nov'}}, 'RevisionHistory': [{'Date': '2025-10-01T23:10:52', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-10-01T23:10:52', 'InitialReleaseDate': '2012-11-02T00:00:00'}} |
CVE-2012-4575 | 2012-Nov | The add_database function in objects.c in the pgbouncer pooler 1.5.2 for PostgreSQL allows remote attackers to cause a denial of service (daemon outage) via a long database name in a request. | 0 | Moderate | 2025-10-01 23:10:52+03:00 | 2020-09-25 00:00:00+03:00 | Moderate | 81bb6050b8ea534ee7991f966737982043b25b320d2eac0101ff42b8d1ee2b48 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2012-Nov', 'vulnerability': {'CVE': 'CVE-2012-4575', 'CWE': [{'ID': 'CWE-119', 'Value': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The add_database function in objects.c in the pgbouncer pooler 1.5.2 for PostgreSQL allows remote attackers to cause a denial of service (daemon outage) via a long database name in a request.'}, 'Ordinal': '2', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19044-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19044-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19044-16820'], 'FixedBuild': '12.7-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19044-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19044-16820']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2012-Nov'}, 'Alias': {'Value': '2012-Nov'}}, 'RevisionHistory': [{'Date': '2025-10-01T23:10:52', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-10-01T23:10:52', 'InitialReleaseDate': '2012-11-02T00:00:00'}} |
CVE-2011-5244 | 2012-Nov | Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, different vulnerabilities than CVE-2010-2642 and CVE-2011-0433. | 0 | Moderate | 2025-10-01 23:10:52+03:00 | 2025-10-01 23:10:52+03:00 | Moderate | 9d21992534aaec39ead00fce87694ee1ef8e6411d03f968a03a344a1dc9cdbab | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2012-Nov', 'vulnerability': {'CVE': 'CVE-2011-5244', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, different vulnerabilities than CVE-2010-2642 and CVE-2011-0433.'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19227-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19227-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19227-16823'], 'FixedBuild': '5.1.2-28', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19227-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19227-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:52', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2012-Nov'}, 'Alias': {'Value': '2012-Nov'}}, 'RevisionHistory': [{'Date': '2025-10-01T23:10:52', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-10-01T23:10:52', 'InitialReleaseDate': '2012-11-02T00:00:00'}} |
CVE-2011-2519 | 2013-Dec | Xen in the Linux kernel when running a guest on a host without hardware assisted paging (HAP) allows guest users to cause a denial of service (invalid pointer dereference and hypervisor crash) via the SAHF instruction. | 0 | Moderate | 2020-09-25 00:00:00+03:00 | 2020-09-25 00:00:00+03:00 | Moderate | 87b5509541302f89c0f16892b2786a8aaf451e3df3763a3d99921971cdc203ff | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2013-Dec', 'vulnerability': {'CVE': 'CVE-2011-2519', 'CWE': [{'ID': 'CWE-476', 'Value': 'NULL Pointer Dereference'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Xen in the Linux kernel when running a guest on a host without hardware assisted paging (HAP) allows guest users to cause a denial of service (invalid pointer dereference and hypervisor crash) via the SAHF instruction.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19218-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19218-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19218-16820'], 'FixedBuild': '5.4.72-3', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19218-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19218-16820']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2013-Dec'}, 'Alias': {'Value': '2013-Dec'}}, 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2020-09-25T00:00:00', 'InitialReleaseDate': '2013-12-02T00:00:00'}} |
CVE-2011-4966 | 2013-Mar | modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenticated users to authenticate using an expired password. | 0 | Moderate | 2026-02-18 03:03:58+03:00 | 2025-10-01 23:10:52+03:00 | Moderate | 939ac68530cd767b1816effae0215a170791789fbce12308112773ea17ad597c | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2013-Mar', 'vulnerability': {'CVE': 'CVE-2011-4966', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenticated users to authenticate using an expired password.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19231-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19231-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19231-16823'], 'FixedBuild': '3.2.3-2', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19231-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19231-16823']}], 'RevisionHistory': [{'Date': '2025-10-01T23:10:52', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2013-Mar'}, 'Alias': {'Value': '2013-Mar'}}, 'RevisionHistory': [{'Date': '2026-02-18T03:03:58', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T03:03:58', 'InitialReleaseDate': '2013-03-02T00:00:00'}} |
CVE-2011-4969 | 2013-Mar | Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag. | 0 | Moderate | 2026-02-18 03:03:58+03:00 | 2025-09-03 21:57:55+03:00 | Moderate | 14d52e7bae8d9d4fe59eff5d3a9aed463d4724195694c5057ba0fd10d0f2c96e | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2013-Mar', 'vulnerability': {'CVE': 'CVE-2011-4969', 'CWE': [{'ID': 'CWE-79', 'Value': 'Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag.'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19693-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['18469-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['20120-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19842-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19693-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['18469-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['20120-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19842-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19693-17084', '18469-17084', '20120-17084', '19842-17084']}], 'RevisionHistory': [{'Date': '2025-09-03T21:57:55', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2026-02-18T03:03:58', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2013-Mar'}, 'Alias': {'Value': '2013-Mar'}}, 'RevisionHistory': [{'Date': '2026-02-18T03:03:58', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T03:03:58', 'InitialReleaseDate': '2013-03-02T00:00:00'}} |
CVE-2013-2094 | 2013-May | The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type which allows local users to gain privileges via a crafted perf_event_open system call. | 0 | Important | 2026-02-18 14:34:24+03:00 | 2024-02-16 00:00:00+03:00 | Important | a515799aa227eb8af2513129a3053e45987dbd3192f75ed5879ec436a3d03abc | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2013-May', 'vulnerability': {'CVE': 'CVE-2013-2094', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type which allows local users to gain privileges via a crafted perf_event_open system call.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16838-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16839-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19793-17086'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['20062-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16838-16823'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16839-17084'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19793-17086'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['20062-17084'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16838-16823', '19793-17086'], 'FixedBuild': '5.15.153.1-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16838-16823', '19793-17086'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16839-17084', '20062-17084'], 'FixedBuild': '6.6.22.1-2', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16839-17084', '20062-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [{'Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'BaseScore': 8.4, 'ProductID': ['16838-16823'], 'TemporalScore': 8.4, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'BaseScore': 8.4, 'ProductID': ['16839-17084'], 'TemporalScore': 8.4, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'BaseScore': 8.4, 'ProductID': ['19793-17086'], 'TemporalScore': 8.4, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'BaseScore': 8.4, 'ProductID': ['20062-17084'], 'TemporalScore': 8.4, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16838-16823', '16839-17084', '19793-17086', '20062-17084']}], 'RevisionHistory': [{'Date': '2024-02-16T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-06-30T07:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2025-02-05T00:00:00', 'Number': '1.2', 'Description': {'Value': '<p>Added kernel to CBL-Mariner 2.0\nAdded kernel to Azure Linux 3.0</p>\n'}}, {'Date': '2026-02-18T14:34:24', 'Number': '1.3', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2013-May'}, 'Alias': {'Value': '2013-May'}}, 'RevisionHistory': [{'Date': '2026-02-18T14:34:24', 'Number': '4', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T14:34:24', 'InitialReleaseDate': '2013-05-02T00:00:00'}} |
CVE-2013-0222 | 2013-Nov | The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the uniq command which triggers a stack-based buffer overflow in the alloca function. | 0 | Low | 2026-02-21 01:38:21+03:00 | 2020-09-25 00:00:00+03:00 | Low | 1332d12efb567e6731a85662e6096786f6c4936e8a8a505417a51ef8757f901e | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2013-Nov', 'vulnerability': {'CVE': 'CVE-2013-0222', 'CWE': [{'ID': 'CWE-119', 'Value': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the uniq command which triggers a stack-based buffer overflow in the alloca function.'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16868-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16868-16820'], 'Description': {'Value': 'Low'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16868-16820'], 'FixedBuild': '8.30-7', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16868-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16868-16820']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2013-Nov'}, 'Alias': {'Value': '2013-Nov'}}, 'RevisionHistory': [{'Date': '2026-02-21T01:38:21', 'Number': '6', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-21T01:38:21', 'InitialReleaseDate': '2013-11-02T00:00:00'}} |
CVE-2013-0223 | 2013-Nov | The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the join command when using the -i switch which triggers a stack-based buffer overflow in the alloca function. | 0 | Low | 2026-02-21 01:38:21+03:00 | 2020-09-25 00:00:00+03:00 | Low | 52105888fda4f289f1311ba92669eb0ce19f0b20fb85e16dcaa9e67105a28e97 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2013-Nov', 'vulnerability': {'CVE': 'CVE-2013-0223', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the join command when using the -i switch which triggers a stack-based buffer overflow in the alloca function.'}, 'Ordinal': '2', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16868-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16868-16820'], 'Description': {'Value': 'Low'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16868-16820'], 'FixedBuild': '8.30-7', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16868-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16868-16820']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2013-Nov'}, 'Alias': {'Value': '2013-Nov'}}, 'RevisionHistory': [{'Date': '2026-02-21T01:38:21', 'Number': '6', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-21T01:38:21', 'InitialReleaseDate': '2013-11-02T00:00:00'}} |
CVE-2013-4416 | 2013-Nov | The Ocaml xenstored implementation (oxenstored) in Xen 4.1.x, 4.2.x, and 4.3.x allows local guest domains to cause a denial of service (domain shutdown) via a large message reply. | 0 | Moderate | 2026-02-21 01:38:21+03:00 | 2025-09-03 23:21:14+03:00 | Moderate | 46d7e0eac5b494db25e4fb0b4f8d8691e964256c75a8c3c5e06da837e24048a8 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2013-Nov', 'vulnerability': {'CVE': 'CVE-2013-4416', 'CWE': [{'ID': 'CWE-119', 'Value': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The Ocaml xenstored implementation (oxenstored) in Xen 4.1.x, 4.2.x, and 4.3.x allows local guest domains to cause a denial of service (domain shutdown) via a large message reply.'}, 'Ordinal': '3', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19663-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19663-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19663-17084']}], 'RevisionHistory': [{'Date': '2025-09-03T23:21:14', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2026-02-21T01:38:21', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2013-Nov'}, 'Alias': {'Value': '2013-Nov'}}, 'RevisionHistory': [{'Date': '2026-02-21T01:38:21', 'Number': '6', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-21T01:38:21', 'InitialReleaseDate': '2013-11-02T00:00:00'}} |
CVE-2013-0221 | 2013-Nov | The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the sort command when using the (1) -d or (2) -M switch which triggers a stack-based buffer overflow in the alloca function. | 0 | Moderate | 2026-02-21 01:38:21+03:00 | 2020-09-25 00:00:00+03:00 | Moderate | 05977cd755aa3a6b3eed1f093ffcd74b333e69bede06eb48e0b6736b3dc6dd44 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2013-Nov', 'vulnerability': {'CVE': 'CVE-2013-0221', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the sort command when using the (1) -d or (2) -M switch which triggers a stack-based buffer overflow in the alloca function.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16868-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16868-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16868-16820'], 'FixedBuild': '8.30-7', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16868-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16868-16820']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2013-Nov'}, 'Alias': {'Value': '2013-Nov'}}, 'RevisionHistory': [{'Date': '2026-02-21T01:38:21', 'Number': '6', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-21T01:38:21', 'InitialReleaseDate': '2013-11-02T00:00:00'}} |
CVE-2013-6381 | 2013-Nov | Buffer overflow in the qeth_snmp_command function in drivers/s390/net/qeth_core_main.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service or possibly have unspecified other impact via an SNMP ioctl call with a length value that is incompatible with the command-buffer size. | 0 | Moderate | 2026-02-21 01:38:21+03:00 | 2024-02-10 00:00:00+03:00 | Moderate | dcc3d9614118423aec53b25cb02c5308de914f233d7df5b568b13e7bb9b0e1b7 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2013-Nov', 'vulnerability': {'CVE': 'CVE-2013-6381', 'CWE': [{'ID': 'CWE-119', 'Value': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Buffer overflow in the qeth_snmp_command function in drivers/s390/net/qeth_core_main.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service or possibly have unspecified other impact via an SNMP ioctl call with a length value that is incompatible with the command-buffer size.'}, 'Ordinal': '4', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16960-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17062-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19715-17086'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16839-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16960-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17062-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19715-17086'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16839-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16960-16823', '19715-17086'], 'FixedBuild': '5.15.148.2-2', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16960-16823', '19715-17086'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['17062-17084'], 'FixedBuild': '-', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['17062-17084'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16839-17084'], 'FixedBuild': '6.6.29.1-4', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16839-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16960-16823', '17062-17084', '19715-17086', '16839-17084']}], 'RevisionHistory': [{'Date': '2024-02-10T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-06-30T07:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2026-02-18T14:27:30', 'Number': '1.2', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2013-Nov'}, 'Alias': {'Value': '2013-Nov'}}, 'RevisionHistory': [{'Date': '2026-02-21T01:38:21', 'Number': '6', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-21T01:38:21', 'InitialReleaseDate': '2013-11-02T00:00:00'}} |
CVE-2012-5627 | 2013-Oct | Oracle MySQL and MariaDB 5.5.x before 5.5.29 5.3.x before 5.3.12 and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks. | 0 | Moderate | 2024-06-30 07:00:00+03:00 | 2020-09-25 00:00:00+03:00 | Moderate | 45fc540f2c2bec25990e94b6e2786a7928688d367c24eee8af8b29d0efa041ae | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2013-Oct', 'vulnerability': {'CVE': 'CVE-2012-5627', 'CWE': [{'ID': 'CWE-522', 'Value': 'Insufficiently Protected Credentials'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Oracle MySQL and MariaDB 5.5.x before 5.5.29 5.3.x before 5.3.12 and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19219-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19220-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19219-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19220-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19219-16820'], 'FixedBuild': '8.0.26-2', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19219-16820'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19220-16823'], 'FixedBuild': '8.0.24-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19220-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19219-16820', '19220-16823']}], 'RevisionHistory': [{'Date': '2020-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2021-12-16T00:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Added mysql to CBL-Mariner 2.0</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2013-Oct'}, 'Alias': {'Value': '2013-Oct'}}, 'RevisionHistory': [{'Date': '2024-06-30T07:00:00', 'Number': '4', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2024-06-30T07:00:00', 'InitialReleaseDate': '2013-10-02T00:00:00'}} |
CVE-2013-4342 | 2013-Oct | xinetd does not enforce the user and group configuration directives for TCPMUX services which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service. | 0 | Important | 2024-06-30 07:00:00+03:00 | 2023-02-20 00:00:00+03:00 | Important | 9f31ebfc04a96ecfabfa66b428d383904a74e119fbfbea5d41396c557f051432 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2013-Oct', 'vulnerability': {'CVE': 'CVE-2013-4342', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'xinetd does not enforce the user and group configuration directives for TCPMUX services which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19214-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19215-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19216-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19214-16820'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19215-16823'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19216-17084'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19214-16820'], 'FixedBuild': '2.3.15-13', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19214-16820'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19215-16823', '19216-17084'], 'FixedBuild': '2.3.15-14', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19215-16823', '19216-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19214-16820', '19215-16823', '19216-17084']}], 'RevisionHistory': [{'Date': '2023-02-20T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-06-30T07:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2013-Oct'}, 'Alias': {'Value': '2013-Oct'}}, 'RevisionHistory': [{'Date': '2024-06-30T07:00:00', 'Number': '4', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2024-06-30T07:00:00', 'InitialReleaseDate': '2013-10-02T00:00:00'}} |
CVE-2014-6407 | 2014-Dec | Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation. | 0 | Important | 2024-06-30 07:00:00+03:00 | 2021-07-16 00:00:00+03:00 | Important | f89cba58a82265dddfd53b8d3f94dc790cc1da82c7ee35e9c5533fc1009afd90 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2014-Dec', 'vulnerability': {'CVE': 'CVE-2014-6407', 'CWE': [{'ID': 'CWE-59', 'Value': 'Improper Link Resolution Before File Access ('Link Following')'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16833-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16833-16820'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16833-16820'], 'FixedBuild': '-', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16833-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16833-16820']}], 'RevisionHistory': [{'Date': '2021-07-16T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2014-Dec'}, 'Alias': {'Value': '2014-Dec'}}, 'RevisionHistory': [{'Date': '2024-06-30T07:00:00', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2024-06-30T07:00:00', 'InitialReleaseDate': '2014-12-02T00:00:00'}} |
CVE-2014-9358 | 2014-Dec | Docker before 1.3.3 does not properly validate image IDs which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications." | 0 | Moderate | 2024-06-30 07:00:00+03:00 | 2021-07-16 00:00:00+03:00 | Moderate | e4406b0cb78857ec2254e44d41ca83fffdbd9ecfb72dacb1ecad6e6be66a9329 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2014-Dec', 'vulnerability': {'CVE': 'CVE-2014-9358', 'CWE': [{'ID': 'CWE-20', 'Value': 'Improper Input Validation'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Docker before 1.3.3 does not properly validate image IDs which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."'}, 'Ordinal': '2', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16833-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16833-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16833-16820'], 'FixedBuild': '-', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16833-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16833-16820']}], 'RevisionHistory': [{'Date': '2021-07-16T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2014-Dec'}, 'Alias': {'Value': '2014-Dec'}}, 'RevisionHistory': [{'Date': '2024-06-30T07:00:00', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2024-06-30T07:00:00', 'InitialReleaseDate': '2014-12-02T00:00:00'}} |
CVE-2017-18207 | 2024-Oct | 0 | 2026-05-17 14:47:42+03:00 | 2024-09-26 00:00:00+03:00 | a9351000caf6f56e1fc6618067b0ddc8d798742095fb7c55018ce72db51a145a | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2024-Oct', 'vulnerability': {'CVE': 'CVE-2017-18207', 'Notes': [{'Type': 6, 'Title': 'NIST NVD Details', 'Value': 'https://nvd.nist.gov/vuln/detail/CVE-2017-18207', 'Ordinal': '1'}, {'Type': 6, 'Title': 'NIST NVD Details', 'Value': 'https://nvd.nist.gov/vuln/detail/CVE-2017-18207', 'Ordinal': '1'}, {'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'cve@mitre.org', 'Value': 'cve@mitre.org', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {}, 'Ordinal': '5', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['12139'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['12140'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['12138'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['12139'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['12140'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['12137'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['12138'], 'Description': {}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'CBL-Mariner', 'ProductID': ['12137'], 'FixedBuild': '2.7.18-5', 'Description': {'Value': 'python2'}, 'AffectedFiles': [{'FileName': 'python2-2.7.18-5.cm1.x86_64.rpm', 'FileLastModified': '0001-01-01T00:00:00'}, {'FileName': 'python2-libs-2.7.18-5.cm1.x86_64.rpm', 'FileLastModified': '0001-01-01T00:00:00'}, {'FileName': 'python-xml-2.7.18-5.cm1.x86_64.rpm', 'FileLastModified': '0001-01-01T00:00:00'}, {'FileName': 'python-curses-2.7.18-5.cm1.x86_64.rpm', 'FileLastModified': '0001-01-01T00:00:00'}, {'FileName': 'python2-devel-2.7.18-5.cm1.x86_64.rpm', 'FileLastModified': '0001-01-01T00:00:00'}, {'FileName': 'python2-tools-2.7.18-5.cm1.x86_64.rpm', 'FileLastModified': '0001-01-01T00:00:00'}, {'FileName': 'python2-test-2.7.18-5.cm1.x86_64.rpm', 'FileLastModified': '0001-01-01T00:00:00'}, {'FileName': 'python2-debuginfo-2.7.18-5.cm1.x86_64.rpm', 'FileLastModified': '0001-01-01T00:00:00'}], 'DateSpecified': False, 'RestartRequired': {}}, {'URL': 'https://nvd.nist.gov/vuln/detail/CVE-2017-18207', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'python2', 'ProductID': ['12137'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'CBL-Mariner', 'ProductID': ['12138'], 'FixedBuild': '2.7.18-5', 'Description': {'Value': 'python2'}, 'AffectedFiles': [{'FileName': 'python2-2.7.18-5.cm1.aarch64.rpm', 'FileLastModified': '0001-01-01T00:00:00'}, {'FileName': 'python2-libs-2.7.18-5.cm1.aarch64.rpm', 'FileLastModified': '0001-01-01T00:00:00'}, {'FileName': 'python-xml-2.7.18-5.cm1.aarch64.rpm', 'FileLastModified': '0001-01-01T00:00:00'}, {'FileName': 'python-curses-2.7.18-5.cm1.aarch64.rpm', 'FileLastModified': '0001-01-01T00:00:00'}, {'FileName': 'python2-devel-2.7.18-5.cm1.aarch64.rpm', 'FileLastModified': '0001-01-01T00:00:00'}, {'FileName': 'python2-tools-2.7.18-5.cm1.aarch64.rpm', 'FileLastModified': '0001-01-01T00:00:00'}, {'FileName': 'python2-test-2.7.18-5.cm1.aarch64.rpm', 'FileLastModified': '0001-01-01T00:00:00'}, {'FileName': 'python2-debuginfo-2.7.18-5.cm1.aarch64.rpm', 'FileLastModified': '0001-01-01T00:00:00'}], 'DateSpecified': False, 'RestartRequired': {}}, {'URL': 'https://nvd.nist.gov/vuln/detail/CVE-2017-18207', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'python2', 'ProductID': ['12138'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [{'Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'BaseScore': 6.5, 'ProductID': ['12139'], 'TemporalScore': 6.5, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'BaseScore': 6.5, 'ProductID': ['12140'], 'TemporalScore': 6.5, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'BaseScore': 6.5, 'ProductID': ['12137'], 'TemporalScore': 6.5, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H', 'BaseScore': 6.5, 'ProductID': ['12138'], 'TemporalScore': 6.5, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['12139', '12140', '12137', '12138']}], 'RevisionHistory': [{'Date': '2024-09-26T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-27T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-28T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-29T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-30T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-02T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-04T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-05T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-09T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-15T00:00:00', 'Number': '2.0', 'Description': {'Value': '<p>Added python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-19T00:00:00', 'Number': '6.0', 'Description': {'Value': '<p>Added python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-20T00:00:00', 'Number': '7.0', 'Description': {'Value': '<p>Added python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-21T00:00:00', 'Number': '8.0', 'Description': {'Value': '<p>Added python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-23T00:00:00', 'Number': '10.0', 'Description': {'Value': '<p>Added python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-24T00:00:00', 'Number': '11.0', 'Description': {'Value': '<p>Added python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-28T00:00:00', 'Number': '15.0', 'Description': {'Value': '<p>Added python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-29T00:00:00', 'Number': '16.0', 'Description': {'Value': '<p>Added python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-30T00:00:00', 'Number': '17.0', 'Description': {'Value': '<p>Added python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-31T00:00:00', 'Number': '18.0', 'Description': {'Value': '<p>Added python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2020-08-18T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-06-30T07:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-08T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-09T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-10T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-12T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-13T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-14T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-15T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-16T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-17T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-19T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-20T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-21T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-22T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-23T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-24T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-26T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-27T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-28T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-07-29T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-02T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-03T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-04T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-05T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-06T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-07T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-08T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-09T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-10T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-11T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-12T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-15T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-16T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-17T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-18T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-19T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-20T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-21T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-22T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-23T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-24T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-26T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-27T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-28T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-29T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-30T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-08-31T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-01T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-02T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-03T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-05T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-06T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-07T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-08T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-11T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-12T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-13T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-14T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-15T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-16T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-17T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-18T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-19T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-20T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-21T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-22T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-23T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-24T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-09-25T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-01T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-03T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-06T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-07T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-08T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-10T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-11T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-12T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-13T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-14T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-10-16T00:00:00', 'Number': '3.0', 'Description': {'Value': '<p>Added python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-17T00:00:00', 'Number': '4.0', 'Description': {'Value': '<p>Added python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-18T00:00:00', 'Number': '5.0', 'Description': {'Value': '<p>Added python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-22T00:00:00', 'Number': '9.0', 'Description': {'Value': '<p>Added python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-25T00:00:00', 'Number': '12.0', 'Description': {'Value': '<p>Added python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-26T00:00:00', 'Number': '13.0', 'Description': {'Value': '<p>Added python2 to CBL-Mariner 1.0</p>\n'}}, {'Date': '2024-10-27T00:00:00', 'Number': '14.0', 'Description': {'Value': '<p>Added python2 to CBL-Mariner 1.0</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2024-Oct'}, 'Alias': {'Value': '2024-Oct'}}, 'RevisionHistory': [{'Date': '2026-05-17T14:47:42', 'Number': '630', 'Description': {'Value': 'October 2024 Security Updates'}}], 'CurrentReleaseDate': '2026-05-17T14:47:42', 'InitialReleaseDate': '2024-10-08T07:00:00'}} | |||
CVE-2004-2771 | 2014-Dec | The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address. | 0 | Important | 2024-06-30 07:00:00+03:00 | 2021-12-16 00:00:00+03:00 | Important | e878a7a6f6538c4c263a520e0e73b3319976fb80a41fdc25c9ab8863bc810219 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2014-Dec', 'vulnerability': {'CVE': 'CVE-2004-2771', 'CWE': [{'ID': 'CWE-20', 'Value': 'Improper Input Validation'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19521-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19522-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19521-16823'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19522-17084'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19521-16823'], 'FixedBuild': '12.5-34', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19521-16823'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19522-17084'], 'FixedBuild': '12.5-36', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19522-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19521-16823', '19522-17084']}], 'RevisionHistory': [{'Date': '2021-12-16T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-06-30T07:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2014-Dec'}, 'Alias': {'Value': '2014-Dec'}}, 'RevisionHistory': [{'Date': '2024-06-30T07:00:00', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2024-06-30T07:00:00', 'InitialReleaseDate': '2014-12-02T00:00:00'}} |
CVE-2013-4420 | 2014-Feb | Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file. | 0 | Moderate | 2026-02-18 01:27:51+03:00 | 2020-08-18 00:00:00+03:00 | Moderate | 214f595c4d84bcaddbd37e801411327c1e97511d4dd74779e46a46d1225940dd | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2014-Feb', 'vulnerability': {'CVE': 'CVE-2013-4420', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19222-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19223-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['18850-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19222-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19223-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['18850-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19222-16820', '19223-16823'], 'FixedBuild': '1.2.20-8', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19222-16820', '19223-16823'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['18850-17084'], 'FixedBuild': '1.2.20-11', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['18850-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19222-16820', '19223-16823', '18850-17084']}], 'RevisionHistory': [{'Date': '2020-08-18T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2021-12-16T00:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Added libtar to CBL-Mariner 2.0</p>\n'}}, {'Date': '2024-06-30T07:00:00', 'Number': '1.2', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2014-Feb'}, 'Alias': {'Value': '2014-Feb'}}, 'RevisionHistory': [{'Date': '2026-02-18T01:27:51', 'Number': '6', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T01:27:51', 'InitialReleaseDate': '2014-02-02T00:00:00'}} |
CVE-2014-0069 | 2014-Feb | The cifs_iovec_write function in fs/cifs/file.c in the Linux kernel through 3.13.5 does not properly handle uncached write operations that copy fewer than the requested number of bytes which allows local users to obtain sensitive information from kernel memory cause a denial of service (memory corruption and system crash) or possibly gain privileges via a writev system call with a crafted pointer. | 0 | Important | 2026-02-18 01:27:51+03:00 | 2024-02-06 00:00:00+03:00 | Important | 1239d88a87f9d764879a9559ae4908ba1c3c9a5928effcebc3e2984ec673707f | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2014-Feb', 'vulnerability': {'CVE': 'CVE-2014-0069', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The cifs_iovec_write function in fs/cifs/file.c in the Linux kernel through 3.13.5 does not properly handle uncached write operations that copy fewer than the requested number of bytes which allows local users to obtain sensitive information from kernel memory cause a denial of service (memory corruption and system crash) or possibly gain privileges via a writev system call with a crafted pointer.'}, 'Ordinal': '2', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16960-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17062-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19702-17086'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17065-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16960-16823'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17062-17084'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19702-17086'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17065-17084'], 'Description': {}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16960-16823', '19702-17086'], 'FixedBuild': '5.15.148.2-2', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16960-16823', '19702-17086'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['17062-17084'], 'FixedBuild': '-', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['17062-17084'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['17065-17084'], 'FixedBuild': '6.6.29.1-4', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['17065-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16960-16823', '17062-17084', '19702-17086', '17065-17084']}], 'RevisionHistory': [{'Date': '2024-02-06T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-06-30T07:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2014-Feb'}, 'Alias': {'Value': '2014-Feb'}}, 'RevisionHistory': [{'Date': '2026-02-18T01:27:51', 'Number': '6', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T01:27:51', 'InitialReleaseDate': '2014-02-02T00:00:00'}} |
CVE-2010-4226 | 2014-Feb | cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive. | 0 | Moderate | 2026-02-18 01:27:51+03:00 | 2025-09-03 20:26:05+03:00 | Moderate | 02d3a088f58e20df8fc4024cab9d91e0ed8e0227f929b26042e71c5187a1782f | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2014-Feb', 'vulnerability': {'CVE': 'CVE-2010-4226', 'CWE': [{'ID': 'CWE-59', 'Value': 'Improper Link Resolution Before File Access ('Link Following')'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19011-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19221-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19929-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19011-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19221-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19929-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19011-16820'], 'FixedBuild': '2.13-3', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19011-16820'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['19221-16823'], 'FixedBuild': '2.13-5', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['19221-16823'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [{'Vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'BaseScore': 7.2, 'ProductID': ['19011-16820'], 'TemporalScore': 7.2, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'BaseScore': 7.2, 'ProductID': ['19221-16823'], 'TemporalScore': 7.2, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}, {'Vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H', 'BaseScore': 7.2, 'ProductID': ['19929-17084'], 'TemporalScore': 7.2, 'EnvironmentalScore': 0, 'IsTemporalScoreFieldSpecified': False}], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19011-16820', '19221-16823', '19929-17084']}], 'RevisionHistory': [{'Date': '2025-09-03T20:26:05', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2026-02-18T01:27:51', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2014-Feb'}, 'Alias': {'Value': '2014-Feb'}}, 'RevisionHistory': [{'Date': '2026-02-18T01:27:51', 'Number': '6', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T01:27:51', 'InitialReleaseDate': '2014-02-02T00:00:00'}} |
CVE-2013-0340 | 2014-Jan | expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function which allows remote attackers to cause a denial of service (resource consumption) send HTTP requests to intranet servers or read arbitrary files via a crafted XML document aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion the responsibility for resolving this issue lies with application developers; according to this argument this entry should be REJECTed and each affected application would need its own CVE. | 0 | Moderate | 2021-12-01 00:00:00+03:00 | 2021-12-01 00:00:00+03:00 | Moderate | 7ffc6674f070c2498be1f3194857509e351df30824e4c818afcd1e8196c56eb4 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2014-Jan', 'vulnerability': {'CVE': 'CVE-2013-0340', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function which allows remote attackers to cause a denial of service (resource consumption) send HTTP requests to intranet servers or read arbitrary files via a crafted XML document aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion the responsibility for resolving this issue lies with application developers; according to this argument this entry should be REJECTed and each affected application would need its own CVE.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17018-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17018-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['17018-16820'], 'FixedBuild': '2.4.1-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['17018-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['17018-16820']}], 'RevisionHistory': [{'Date': '2021-12-01T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2014-Jan'}, 'Alias': {'Value': '2014-Jan'}}, 'RevisionHistory': [{'Date': '2021-12-01T00:00:00', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2021-12-01T00:00:00', 'InitialReleaseDate': '2014-01-02T00:00:00'}} |
CVE-2013-6418 | 2014-May | PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate. | 0 | Moderate | 2025-09-03 23:39:48+03:00 | 2025-09-03 23:39:48+03:00 | Moderate | d7604ed903835f5432168755e62cb01dffe549595e12ac2820de913e9f40cf2a | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2014-May', 'vulnerability': {'CVE': 'CVE-2013-6418', 'CWE': [{'ID': 'CWE-20', 'Value': 'Improper Input Validation'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19871-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19871-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19871-17084']}], 'RevisionHistory': [{'Date': '2025-09-03T23:39:48', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2014-May'}, 'Alias': {'Value': '2014-May'}}, 'RevisionHistory': [{'Date': '2025-09-03T23:39:48', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2025-09-03T23:39:48', 'InitialReleaseDate': '2014-05-02T00:00:00'}} |
CVE-2014-5277 | 2014-Nov | Docker before 1.3.1 and docker-py before 0.5.3 fall back to HTTP when the HTTPS connection to the registry fails which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and the registry to block HTTPS traffic. | 0 | Moderate | 2026-02-18 01:44:50+03:00 | 2021-07-16 00:00:00+03:00 | Moderate | 5f8420ee15aa781e707bd30bf3941340673afc7f7ea005f8e14ebf87c3951ff3 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2014-Nov', 'vulnerability': {'CVE': 'CVE-2014-5277', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Docker before 1.3.1 and docker-py before 0.5.3 fall back to HTTP when the HTTPS connection to the registry fails which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and the registry to block HTTPS traffic.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16833-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16833-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16833-16820'], 'FixedBuild': '-', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16833-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16833-16820']}], 'RevisionHistory': [{'Date': '2021-07-16T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2014-Nov'}, 'Alias': {'Value': '2014-Nov'}}, 'RevisionHistory': [{'Date': '2026-02-18T01:44:50', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T01:44:50', 'InitialReleaseDate': '2014-11-02T00:00:00'}} |
CVE-2014-8991 | 2014-Nov | pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user. | 0 | Low | 2026-02-18 01:44:50+03:00 | 2025-09-03 21:14:33+03:00 | Low | 666695f81d71c291039974d6c130409d1b272eebe2e980054831f8e4579c9d70 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2014-Nov', 'vulnerability': {'CVE': 'CVE-2014-8991', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['17713-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['17713-17084'], 'Description': {'Value': 'Low'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['17713-17084']}], 'RevisionHistory': [{'Date': '2025-09-03T21:14:33', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2026-02-18T01:44:50', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2014-Nov'}, 'Alias': {'Value': '2014-Nov'}}, 'RevisionHistory': [{'Date': '2026-02-18T01:44:50', 'Number': '3', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T01:44:50', 'InitialReleaseDate': '2014-11-02T00:00:00'}} |
CVE-2014-7204 | 2014-Oct | jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file. | 0 | Moderate | 2021-07-30 00:00:00+03:00 | 2021-07-30 00:00:00+03:00 | Moderate | 525d73e237ddbda70bea8f463988d6a02bb209463faf4fb7aa407fe1b2a9f9c1 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2014-Oct', 'vulnerability': {'CVE': 'CVE-2014-7204', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['18510-16820'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['18510-16820'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['18510-16820'], 'FixedBuild': '5.8-6', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['18510-16820'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['18510-16820']}], 'RevisionHistory': [{'Date': '2021-07-30T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2014-Oct'}, 'Alias': {'Value': '2014-Oct'}}, 'RevisionHistory': [{'Date': '2021-07-30T00:00:00', 'Number': '1', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2021-07-30T00:00:00', 'InitialReleaseDate': '2014-10-02T00:00:00'}} |
CVE-2014-5461 | 2014-Sep | Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments. | 0 | Moderate | 2026-02-18 14:35:04+03:00 | 2026-02-18 14:31:32+03:00 | Moderate | 0acdd7816c766e9af7d0798494de0d302ebffdcf37e6b9280c8b985fb5dae4a8 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2014-Sep', 'vulnerability': {'CVE': 'CVE-2014-5461', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.'}, 'Ordinal': '2', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16855-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19666-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16855-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19666-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16855-17084', '19666-17084'], 'FixedBuild': '18.2.2-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16855-17084', '19666-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16855-17084', '19666-17084']}], 'RevisionHistory': [{'Date': '2026-02-18T14:31:32', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2025-09-03T21:01:20', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2014-Sep'}, 'Alias': {'Value': '2014-Sep'}}, 'RevisionHistory': [{'Date': '2026-02-18T14:35:04', 'Number': '6', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T14:35:04', 'InitialReleaseDate': '2014-09-02T00:00:00'}} |
CVE-2014-3185 | 2014-Sep | Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat.c in the Whiteheat USB Serial Driver in the Linux kernel before 3.16.2 allow physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with a bulk response. | 0 | Moderate | 2026-02-18 14:35:04+03:00 | 2026-02-18 14:35:04+03:00 | Moderate | 75837cb80885394e8ccaa90572a47ec810abef97c3e318dff9ba37ab4e0f9917 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2014-Sep', 'vulnerability': {'CVE': 'CVE-2014-3185', 'CWE': [{'ID': 'CWE-119', 'Value': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'Chrome', 'Value': 'Chrome', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat.c in the Whiteheat USB Serial Driver in the Linux kernel before 3.16.2 allow physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with a bulk response.'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16838-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16839-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19793-17086'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19779-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16838-16823'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16839-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19793-17086'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19779-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16838-16823', '19793-17086'], 'FixedBuild': '5.15.153.1-1', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16838-16823', '19793-17086'], 'AffectedFiles': [], 'DateSpecified': False}, {'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16839-17084', '19779-17084'], 'FixedBuild': '6.6.22.1-2', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16839-17084', '19779-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16838-16823', '16839-17084', '19793-17086', '19779-17084']}], 'RevisionHistory': [{'Date': '2026-02-18T14:35:04', 'Number': '1.2', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-02-16T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-06-30T07:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2014-Sep'}, 'Alias': {'Value': '2014-Sep'}}, 'RevisionHistory': [{'Date': '2026-02-18T14:35:04', 'Number': '6', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T14:35:04', 'InitialReleaseDate': '2014-09-02T00:00:00'}} |
CVE-2014-3618 | 2014-Sep | Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted email header related to "unbalanced quotes." | 0 | Important | 2026-02-18 14:35:04+03:00 | 2021-12-16 00:00:00+03:00 | Important | 902177c1afabb632820df59358637c020887967c7f9ae183ddd9678ffead5914 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2014-Sep', 'vulnerability': {'CVE': 'CVE-2014-3618', 'CWE': [{'ID': 'CWE-119', 'Value': 'Improper Restriction of Operations within the Bounds of a Memory Buffer'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'redhat', 'Value': 'redhat', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted email header related to "unbalanced quotes."'}, 'Ordinal': '1', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16902-16823'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16903-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16902-16823'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16903-17084'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16902-16823', '16903-17084'], 'FixedBuild': '3.22-53', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16902-16823', '16903-17084'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16902-16823', '16903-17084']}], 'RevisionHistory': [{'Date': '2021-12-16T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2024-06-30T07:00:00', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2014-Sep'}, 'Alias': {'Value': '2014-Sep'}}, 'RevisionHistory': [{'Date': '2026-02-18T14:35:04', 'Number': '6', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T14:35:04', 'InitialReleaseDate': '2014-09-02T00:00:00'}} |
CVE-2015-3416 | 2015-Apr | The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-based buffer overflow) or possibly have unspecified other impact via large integers in a crafted printf function call in a SELECT statement. | 0 | Important | 2026-02-18 14:56:51+03:00 | 2025-09-03 23:33:38+03:00 | Important | 4e60967a98668da28716a19891eb086c26152d2ffe6ad4b0b1234b1ddf4a2e59 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2015-Apr', 'vulnerability': {'CVE': 'CVE-2015-3416', 'CWE': [{'ID': 'CWE-190', 'Value': 'Integer Overflow or Wraparound'}], 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-based buffer overflow) or possibly have unspecified other impact via large integers in a crafted printf function call in a SELECT statement.'}, 'Ordinal': '2', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['19212-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['19212-17084'], 'Description': {'Value': 'Important'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['19212-17084']}], 'RevisionHistory': [{'Date': '2025-09-03T23:33:38', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}, {'Date': '2026-02-18T14:56:51', 'Number': '1.1', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2015-Apr'}, 'Alias': {'Value': '2015-Apr'}}, 'RevisionHistory': [{'Date': '2026-02-18T14:56:51', 'Number': '4', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T14:56:51', 'InitialReleaseDate': '2015-04-02T00:00:00'}} |
CVE-2015-1473 | 2015-Apr | The GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a denial of service | 0 | Moderate | 2026-02-18 14:56:51+03:00 | 2025-04-12 00:00:00+03:00 | Moderate | 5168b668192a56796b4a36c41ef378bdca2cd89e6c74d92e9c380852eaceb2e7 | 2026-05-28 21:44:33.824951+03:00 | 2026-05-28 21:44:33.824951+03:00 | {'document_id': '2015-Apr', 'vulnerability': {'CVE': 'CVE-2015-1473', 'Notes': [{'Type': 2, 'Title': 'Description', 'Ordinal': '0'}, {'Type': 4, 'Title': 'FAQ', 'Value': '<p><strong>Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?</strong></p>\n<p>One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See <a href="https://www.microsoft.com/en-us/msrc/blog/2025/10/toward-greater-transparency-machine-readable-vulnerability-exploitability-xchange-for-azure-linux">this blog</a> post for more information. If impact to additional products is identified, we will update the CVE to reflect this.</p>\n', 'Ordinal': '10'}, {'Type': 7, 'Title': 'Mariner', 'Value': 'Mariner', 'Ordinal': '20'}, {'Type': 8, 'Title': 'mitre', 'Value': 'mitre', 'Ordinal': '30'}, {'Type': 6, 'Title': 'Customer Action Required', 'Value': 'Yes', 'Ordinal': '40'}], 'Title': {'Value': 'The GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a denial of service'}, 'Ordinal': '0', 'Threats': [{'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16819-17084'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 0, 'ProductID': ['16819-16817'], 'Description': {}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16819-17084'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}, {'Date': '0001-01-01T00:00:00', 'Type': 3, 'ProductID': ['16819-16817'], 'Description': {'Value': 'Moderate'}, 'DateSpecified': False}], 'ReleaseDate': '0001-01-01T00:00:00', 'Remediations': [{'URL': '', 'Date': '0001-01-01T00:00:00', 'Type': 2, 'SubType': 'Security Update', 'ProductID': ['16819-17084', '16819-16817'], 'FixedBuild': '0.34-7', 'Description': {'Value': 'CBL-Mariner Releases'}, 'AffectedFiles': [], 'DateSpecified': False, 'RestartRequired': {'Value': 'No'}}, {'URL': 'https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade', 'Date': '0001-01-01T00:00:00', 'Type': 3, 'SubType': 'CBL-Mariner Releases', 'ProductID': ['16819-17084', '16819-16817'], 'AffectedFiles': [], 'DateSpecified': False}], 'CVSSScoreSets': [], 'DiscoveryDate': '0001-01-01T00:00:00', 'Acknowledgments': [], 'ProductStatuses': [{'Type': 3, 'ProductID': ['16819-17084', '16819-16817']}], 'RevisionHistory': [{'Date': '2025-04-12T00:00:00', 'Number': '1.0', 'Description': {'Value': '<p>Information published.</p>\n'}}], 'ReleaseDateSpecified': False, 'DiscoveryDateSpecified': False}, 'document_tracking': {'Status': 2, 'Version': '1.0', 'Identification': {'ID': {'Value': '2015-Apr'}, 'Alias': {'Value': '2015-Apr'}}, 'RevisionHistory': [{'Date': '2026-02-18T14:56:51', 'Number': '4', 'Description': {'Value': 'Mariner Release Notes'}}], 'CurrentReleaseDate': '2026-02-18T14:56:51', 'InitialReleaseDate': '2015-04-02T00:00:00'}} |