Known vulnerabilities in trafficserver - page 3
Vendor:
Fedoraproject
Software:
trafficserver
Software CPE:
cpe:2.3:o:fedoraproject:trafficserver:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
61
Public exploits:
1
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
10.2.0-1.fc43
10.2.0-1.fc44
10.1.4-1.fc43
10.1.4-1.fc44
9.2.15-1.el9
9.2.15-1.el8
10.1.3-1.fc43
10.1.3-1.fc44
9.2.14-1.el9
9.2.14-1.el8
10.1.2-1.fc43
10.1.2-1.fc44
10.1.2-1.fc42
9.2.13-1.el9
9.2.13-1.el8
5.3.0-1.fc21
5.3.0-1.fc22
5.3.0-1.el6
5.3.0-1.el7
9.2.10-1.fc40
9.2.10-1.el9
10.0.5-1.fc42
9.2.10-1.fc41
9.2.10-1.el8
9.2.9-1.fc40
9.2.9-1.el9
9.2.9-1.el8
9.2.9-1.fc41
9.1.4-1.fc36
9.1.4-1.el7
9.1.4-1.fc37
9.1.4-1.el8
9.1.4-1.el9
9.1.3-1.el9
9.1.3-1.el8
9.1.3-1.el7
9.1.3-1.fc35
9.1.3-1.fc36
9.2.6-2.fc39
9.2.6-2.fc40
9.2.6-2.fc41
9.2.6-2.el9
9.2.6-2.el8
9.2.5-1.el8
9.2.5-1.fc40
9.2.5-1.el9
9.2.5-1.fc39
9.2.4-1.fc39
9.2.4-1.fc38
9.2.4-1.fc40
9.2.4-1.el8
9.2.4-1.el9
9.2.4-1.el7
9.2.3-1.el7
9.2.3-1.el8
9.2.3-1.el9
9.2.3-1.fc37
9.2.3-1.fc39
9.2.3-1.fc38
9.2.1-1.el7
9.2.1-1.fc38
9.2.1-1.fc37
9.2.1-1.el8
9.2.1-1.el9
Vulnerabilities (61)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU100503 - Improper input validation CVE-2024-38479 |
CWE-20 | Medium | 9.2.6-2.el8, 9.2.6-2.el9, 9.2.6-2.fc39, 9.2.6-2.fc40, 9.2.6-2.fc41 | 14.11.2024 |
SB2024111440 SB2024111444 SB2024111445 and 6 more |
||
| #VU100502 - Improper input validation CVE-2024-50305 |
CWE-20 | Medium | 9.2.6-2.el8, 9.2.6-2.el9, 9.2.6-2.fc39, 9.2.6-2.fc40, 9.2.6-2.fc41 | 14.11.2024 |
SB2024111440 SB2024111444 SB2024111445 and 7 more |
||
| #VU100501 - Unchecked Return Value CVE-2024-50306 |
CWE-252 | Low | 9.2.6-2.el8, 9.2.6-2.el9, 9.2.6-2.fc39, 9.2.6-2.fc40, 9.2.6-2.fc41 | 14.11.2024 |
SB2024111440 SB2024111444 SB2024111445 and 6 more |
||
| #VU96509 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2024-35296 |
CWE-444 | Medium | 9.2.5-1.el8, 9.2.5-1.el9, 9.2.5-1.fc39, 9.2.5-1.fc40 | 26.08.2024 |
SB2024081226 SB2024082632 SB2024082633 and 4 more |
||
| #VU95787 - Improper input validation CVE-2024-35161 |
CWE-20 | High | 9.2.5-1.el8, 9.2.5-1.el9, 9.2.5-1.fc39, 9.2.5-1.fc40 | 12.08.2024 |
SB2024081226 SB2024082632 SB2024082633 and 3 more |
||
| #VU95786 - Improper input validation CVE-2023-38522 |
CWE-20 | Medium | 9.2.5-1.el8, 9.2.5-1.el9, 9.2.5-1.fc39, 9.2.5-1.fc40 | 12.08.2024 |
SB2024081226 SB2024082632 SB2024082633 and 3 more |
||
| #VU88113 - Resource exhaustion CVE-2024-31309 |
CWE-400 | Medium | 9.2.4-1.el7, 9.2.4-1.el8, 9.2.4-1.el9, 9.2.4-1.fc38, 9.2.4-1.fc39, 9.2.4-1.fc40 | 04.04.2024 |
SB2024040404 SB2024040406 SB2024040407 and 5 more |
||
| #VU82989 - Improper input validation CVE-2023-39456 |
CWE-20 | Medium | 9.2.3-1.el7, 9.2.3-1.el8, 9.2.3-1.el9, 9.2.3-1.fc37, 9.2.3-1.fc38, 9.2.3-1.fc39 | 10.11.2023 |
SB2023111062 SB2023111063 SB2023111065 and 6 more |
||
| #VU82988 - Exposure of sensitive information to an unauthorized actor CVE-2023-41752 |
CWE-200 | Medium | 9.2.3-1.el7, 9.2.3-1.el8, 9.2.3-1.el9, 9.2.3-1.fc37, 9.2.3-1.fc38, 9.2.3-1.fc39 | 10.11.2023 |
SB2023111062 SB2023111063 SB2023111065 and 5 more |
||
| #VU81728 - Resource exhaustion CVE-2023-44487 |
CWE-400 | High | 9.2.3-1.el7, 9.2.3-1.el8, 9.2.3-1.el9, 9.2.3-1.fc37, 9.2.3-1.fc38, 9.2.3-1.fc39 | 10.10.2023 |
SB2023101023 SB2023101024 SB2023101037 and 650 more |
||
| #VU79781 - Exposure of sensitive information to an unauthorized actor CVE-2023-33933 |
CWE-200 | Medium | 9.2.1-1.el7, 9.2.1-1.el8, 9.2.1-1.el9, 9.2.1-1.fc37, 9.2.1-1.fc38 | 21.08.2023 |
SB2023082130 SB2023082132 SB2023082154 and 7 more |
||
| #VU79780 - Configuration CVE-2023-30631 |
CWE-16 | Low | 9.2.1-1.el7, 9.2.1-1.el8, 9.2.1-1.el9, 9.2.1-1.fc37, 9.2.1-1.fc38 | 21.08.2023 |
SB2023082130 SB2023082132 SB2023082154 and 4 more |
||
| #VU79779 - Exposure of sensitive information to an unauthorized actor CVE-2022-47184 |
CWE-200 | Medium | 9.2.1-1.el7, 9.2.1-1.el8, 9.2.1-1.el9, 9.2.1-1.fc37, 9.2.1-1.fc38 | 21.08.2023 |
SB2023082130 SB2023082132 SB2023082154 and 7 more |
||
| #VU70791 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2022-40743 |
CWE-79 | Medium | 9.1.4-1.el7, 9.1.4-1.el8, 9.1.4-1.el9, 9.1.4-1.fc36, 9.1.4-1.fc37 | 09.01.2023 |
SB2023010902 SB2022123020 SB2022123022 and 5 more |
||
| #VU70790 - Improper Check for Unusual or Exceptional Conditions CVE-2022-37392 |
CWE-754 | Medium | 9.1.4-1.el7, 9.1.4-1.el8, 9.1.4-1.el9, 9.1.4-1.fc36, 9.1.4-1.fc37 | 09.01.2023 |
SB2023010901 SB2023010902 SB2022123020 and 6 more |
||
| #VU70789 - Improper Check for Unusual or Exceptional Conditions CVE-2022-32749 |
CWE-754 | Medium | 9.1.4-1.el7, 9.1.4-1.el8, 9.1.4-1.el9, 9.1.4-1.fc36, 9.1.4-1.fc37 | 09.01.2023 |
SB2023010901 SB2023010902 SB2022123020 and 6 more |
||
| #VU66509 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-31779 |
CWE-444 | Medium | 9.1.3-1.el7, 9.1.3-1.el8, 9.1.3-1.el9, 9.1.3-1.fc35, 9.1.3-1.fc36 | 15.08.2022 |
SB2022081549 SB2022081550 SB2022082552 and 6 more |
||
| #VU66507 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-28129 |
CWE-444 | Medium | 9.1.3-1.el7, 9.1.3-1.el8, 9.1.3-1.el9, 9.1.3-1.fc35, 9.1.3-1.fc36 | 15.08.2022 |
SB2022081549 SB2022081550 SB2022081141 and 4 more |
||
| #VU66506 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-25763 |
CWE-444 | Medium | 9.1.3-1.el7, 9.1.3-1.el8, 9.1.3-1.el9, 9.1.3-1.fc35, 9.1.3-1.fc36 | 15.08.2022 |
SB2022081549 SB2022081550 SB2022081141 and 4 more |
||
| #VU66504 - Improper Authorization CVE-2021-37150 |
CWE-285 | Medium | 9.1.3-1.el7, 9.1.3-1.el8, 9.1.3-1.el9, 9.1.3-1.fc35, 9.1.3-1.fc36 | 15.08.2022 |
SB2022081549 SB2022081550 SB2022081141 and 4 more |
Showing elements 41 - 60 out of 61