Known vulnerabilities in Open Enclave SDK

Vendor: Microsoft
Software CPE: cpe:2.3:a:microsoft:open_enclave_sdk:*:*:*:*:*:*:*:*
Total vulnerabilities: 11
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Open Enclave SDK Open Enclave SDK is affected by 11 known vulnerabilities: 1 high, 5 medium, 5 low Critical High Medium Low

Vulnerabilities (11)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU71996 - Double Free
CVE-2022-4450
CWE-415 Medium
No
No
0.18.5 07.02.2023 SB2023020742
SB2023020748
SB2023020771
and 180 more
#VU71995 - Use After Free
CVE-2023-0215
CWE-416 Medium
No
No
0.18.5 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 209 more
#VU71993 - Information Exposure Through Timing Discrepancy
CVE-2022-4304
CWE-208 Medium
No
No
0.18.5 07.02.2023 SB2023020742
SB2023020748
SB2023020767
and 222 more
#VU71992 - Type confusion
CVE-2023-0286
CWE-843 High
No
No
0.18.5 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 223 more
#VU66522 - Exposure of sensitive information to an unauthorized actor
CVE-2022-21233
CWE-200 Low
No
No
0.18.2 16.08.2022 SB2022081610
SB2022081724
SB2022081725
and 20 more
#VU64366 - Exposure of sensitive information to an unauthorized actor
CVE-2022-21166
CWE-200 Low
No
No
0.18.0 14.06.2022 SB2022061454
SB2022061466
SB2022061463
and 102 more
#VU61391 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-0778
CWE-835 Medium
Available
No
0.17.7 15.03.2022 SB2022031520
SB2022031522
SB2022031611
and 238 more
#VU54821 - Permissions, Privileges, and Access Controls
CVE-2021-33767
CWE-264 Low
No
No
0.17.1 13.07.2021 SB2021071371
#VU48579 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-28928
CWE-835 Medium
No
No
0.15.0 20.11.2020 SB2020112013
SB2020112104
SB2020112617
and 10 more
#VU22709 - Out-of-bounds read
CVE-2019-1370
CWE-125 Low
No
No
- 12.11.2019 SB2019111316
#VU21663 - Exposure of sensitive information to an unauthorized actor
CVE-2019-1369
CWE-200 Low
No
No
0.7.0 09.10.2019 SB2019100922