Open Source Vulnerabilities
CVE-2023-38432 does not affect BellSoft software
CVE-2023-38431 does not affect BellSoft software
CVE-2023-38430 does not affect BellSoft software
CVE-2023-38428 does not affect BellSoft software
CVE-2023-38427 does not affect BellSoft software
webkit2gtk3, webkit2gtk3-devel, webkit2gtk3-jsc, webkit2gtk3-jsc-devel
Important: webkit2gtk3 security update
webkit2gtk3/ webkit2gtk3-devel/ webkit2gtk3-jsc/ webkit2gtk3-jsc-devel
Important: webkit2gtk3 security update
webkit2gtk3, webkit2gtk3-devel, webkit2gtk3-jsc, webkit2gtk3-jsc-devel
Important: webkit2gtk3 security update
webkit2gtk3/ webkit2gtk3-devel/ webkit2gtk3-jsc/ webkit2gtk3-jsc-devel
Important: webkit2gtk3 security update
kernel
CVE-2023-38409 affecting package kernel for versions less than 5.15.122.1-2
kernel
CVE-2023-38409 affecting package kernel for versions less than 5.15.122.1-2
mariadb
CVE-2023-3724 affecting package mariadb for versions less than 10.6.9-3.cm2
mariadb
CVE-2023-3724 affecting package mariadb for versions less than 10.6.9-3.cm2
hyperv-daemons
CVE-2023-38409 affecting package hyperv-daemons for versions less than 5.15.122.1-1
hyperv-daemons
CVE-2023-38409 affecting package hyperv-daemons for versions less than 5.15.122.1-1
linux-hwe-edge, linux-aws-5.0, linux-aws-5.3, linux-azure, linux-azure-5.3, linux-azure-edge, linux-gcp, linux-gcp-5.3, linux-gke-4.15, linux-gke-5.4, linux-gkeop-5.4, linux-hwe, linux-hwe-edge, linux-oem, linux-oracle-5.0, linux-oracle-5.3, linux-aws-5.11, linux-aws-5.13, linux-aws-5.8, linux-azure-5.11, linux-azure-5.13, linux-azure-5.8, linux-gcp-5.11, linux-gcp-5.13, linux-gcp-5.8, linux-gke, linux-gke-5.15, linux-hwe-5.11, linux-hwe-5.13, linux-hwe-5.8, linux-intel-5.13, linux-oem-5.10, linux-oem-5.13, linux-oem-5.14, linux-oem-5.6, linux-oracle-5.11, linux-oracle-5.13, linux-oracle-5.8, linux-raspi2, linux-riscv, linux-riscv-5.11, linux-riscv-5.8, linux-allwinner-5.19, linux-aws-5.19, linux-azure-5.19, linux-azure-fde-5.19, linux-gcp-5.19, linux-hwe-5.19, linux-lowlatency-hwe-5.19, linux-oem-6.0, linux-oem-6.1, linux-riscv, linux-riscv-5.19, linux-starfive-5.19
linux-hwe-edge/ linux-aws-5.0/ linux-aws-5.3/ linux-azure/ linux-azure-5.3/ linux-azure-edge/ linux-gcp/ linux-gcp-5.3/ linux-gke-4.15/ linux-gke-5.4/ linux-gkeop-5.4/ linux-hwe/ linux-hwe-edge/ linux-oem/ linux-oracle-5.0/ linux-oracle-5.3/ linux-aws-5.11/ linux-aws-5.13/ linux-aws-5.8/ linux-azure-5.11/ linux-azure-5.13/ linux-azure-5.8/ linux-gcp-5.11/ linux-gcp-5.13/ linux-gcp-5.8/ linux-gke/ linux-gke-5.15/ linux-hwe-5.11/ linux-hwe-5.13/ linux-hwe-5.8/ linux-intel-5.13/ linux-oem-5.10/ linux-oem-5.13/ linux-oem-5.14/ linux-oem-5.6/ linux-oracle-5.11/ linux-oracle-5.13/ linux-oracle-5.8/ linux-raspi2/ linux-riscv/ linux-riscv-5.11/ linux-riscv-5.8/ linux-allwinner-5.19/ linux-aws-5.19/ linux-azure-5.19/ linux-azure-fde-5.19/ linux-gcp-5.19/ linux-hwe-5.19/ linux-lowlatency-hwe-5.19/ linux-oem-6.0/ linux-oem-6.1/ linux-riscv/ linux-riscv-5.19/ linux-starfive-5.19
wolfssl, wolfssl, wolfssl, wolfssl, wolfssl, wolfssl, wolfssl
wolfssl/ wolfssl/ wolfssl/ wolfssl/ wolfssl/ wolfssl/ wolfssl
Improper sanitization of MXCSR and RFLAGS in OpenEnclave
iperf3
CVE-2023-38403 affecting package iperf3 for versions less than 3.14-1
iperf3
CVE-2023-38403 affecting package iperf3 for versions less than 3.14-1
iperf3, iperf3, iperf3, iperf3, iperf3, iperf3, iperf3
TLS 1.3 client issue handling malicious server when not including a KSE and PSK extension
TLS 1.3 client issue handling malicious server when not including a KSE and PSK extension
Incorrect identification of source IP addresses in CasaOS
Weak json web token (JWT) secrets in CasaOS
pixman
CVE-2023-37769 affecting package pixman 0.42.2-1
faust, faust, faust, faust, faust, faust, faust
pixman, pixman, pixman, pixman, pixman, pixman, pixman, pixman
pixman/ pixman/ pixman/ pixman/ pixman/ pixman/ pixman/ pixman
topgrade
topgrade Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_all
topgrade
topgrade Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_all
