Known vulnerabilities in trafficserver - page 3

Software: trafficserver
Software CPE: cpe:2.3:o:fedoraproject:trafficserver:*:*:*:*:*:fedora:*:*
Total vulnerabilities: 61
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting trafficserver trafficserver is affected by 61 known vulnerabilities: 18 high, 41 medium, 2 low Critical High Medium Low

Vulnerabilities (61)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU100503 - Improper input validation
CVE-2024-38479
CWE-20 Medium
No
No
9.2.6-2.el8, 9.2.6-2.el9, 9.2.6-2.fc39, 9.2.6-2.fc40, 9.2.6-2.fc41 14.11.2024 SB2024111440
SB2024111444
SB2024111445
and 6 more
#VU100502 - Improper input validation
CVE-2024-50305
CWE-20 Medium
No
No
9.2.6-2.el8, 9.2.6-2.el9, 9.2.6-2.fc39, 9.2.6-2.fc40, 9.2.6-2.fc41 14.11.2024 SB2024111440
SB2024111444
SB2024111445
and 7 more
#VU100501 - Unchecked Return Value
CVE-2024-50306
CWE-252 Low
No
No
9.2.6-2.el8, 9.2.6-2.el9, 9.2.6-2.fc39, 9.2.6-2.fc40, 9.2.6-2.fc41 14.11.2024 SB2024111440
SB2024111444
SB2024111445
and 6 more
#VU96509 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2024-35296
CWE-444 Medium
No
No
9.2.5-1.el8, 9.2.5-1.el9, 9.2.5-1.fc39, 9.2.5-1.fc40 26.08.2024 SB2024081226
SB2024082632
SB2024082633
and 4 more
#VU95787 - Improper input validation
CVE-2024-35161
CWE-20 High
No
No
9.2.5-1.el8, 9.2.5-1.el9, 9.2.5-1.fc39, 9.2.5-1.fc40 12.08.2024 SB2024081226
SB2024082632
SB2024082633
and 3 more
#VU95786 - Improper input validation
CVE-2023-38522
CWE-20 Medium
No
No
9.2.5-1.el8, 9.2.5-1.el9, 9.2.5-1.fc39, 9.2.5-1.fc40 12.08.2024 SB2024081226
SB2024082632
SB2024082633
and 3 more
#VU88113 - Resource exhaustion
CVE-2024-31309
CWE-400 Medium
No
No
9.2.4-1.el7, 9.2.4-1.el8, 9.2.4-1.el9, 9.2.4-1.fc38, 9.2.4-1.fc39, 9.2.4-1.fc40 04.04.2024 SB2024040404
SB2024040406
SB2024040407
and 5 more
#VU82989 - Improper input validation
CVE-2023-39456
CWE-20 Medium
No
No
9.2.3-1.el7, 9.2.3-1.el8, 9.2.3-1.el9, 9.2.3-1.fc37, 9.2.3-1.fc38, 9.2.3-1.fc39 10.11.2023 SB2023111062
SB2023111063
SB2023111065
and 6 more
#VU82988 - Exposure of sensitive information to an unauthorized actor
CVE-2023-41752
CWE-200 Medium
No
No
9.2.3-1.el7, 9.2.3-1.el8, 9.2.3-1.el9, 9.2.3-1.fc37, 9.2.3-1.fc38, 9.2.3-1.fc39 10.11.2023 SB2023111062
SB2023111063
SB2023111065
and 5 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Available
Exploited
9.2.3-1.el7, 9.2.3-1.el8, 9.2.3-1.el9, 9.2.3-1.fc37, 9.2.3-1.fc38, 9.2.3-1.fc39 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 650 more
#VU79781 - Exposure of sensitive information to an unauthorized actor
CVE-2023-33933
CWE-200 Medium
No
No
9.2.1-1.el7, 9.2.1-1.el8, 9.2.1-1.el9, 9.2.1-1.fc37, 9.2.1-1.fc38 21.08.2023 SB2023082130
SB2023082132
SB2023082154
and 7 more
#VU79780 - Configuration
CVE-2023-30631
CWE-16 Low
No
No
9.2.1-1.el7, 9.2.1-1.el8, 9.2.1-1.el9, 9.2.1-1.fc37, 9.2.1-1.fc38 21.08.2023 SB2023082130
SB2023082132
SB2023082154
and 4 more
#VU79779 - Exposure of sensitive information to an unauthorized actor
CVE-2022-47184
CWE-200 Medium
No
No
9.2.1-1.el7, 9.2.1-1.el8, 9.2.1-1.el9, 9.2.1-1.fc37, 9.2.1-1.fc38 21.08.2023 SB2023082130
SB2023082132
SB2023082154
and 7 more
#VU70791 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-40743
CWE-79 Medium
No
No
9.1.4-1.el7, 9.1.4-1.el8, 9.1.4-1.el9, 9.1.4-1.fc36, 9.1.4-1.fc37 09.01.2023 SB2023010902
SB2022123020
SB2022123022
and 5 more
#VU70790 - Improper Check for Unusual or Exceptional Conditions
CVE-2022-37392
CWE-754 Medium
No
No
9.1.4-1.el7, 9.1.4-1.el8, 9.1.4-1.el9, 9.1.4-1.fc36, 9.1.4-1.fc37 09.01.2023 SB2023010901
SB2023010902
SB2022123020
and 6 more
#VU70789 - Improper Check for Unusual or Exceptional Conditions
CVE-2022-32749
CWE-754 Medium
No
No
9.1.4-1.el7, 9.1.4-1.el8, 9.1.4-1.el9, 9.1.4-1.fc36, 9.1.4-1.fc37 09.01.2023 SB2023010901
SB2023010902
SB2022123020
and 6 more
#VU66509 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-31779
CWE-444 Medium
No
No
9.1.3-1.el7, 9.1.3-1.el8, 9.1.3-1.el9, 9.1.3-1.fc35, 9.1.3-1.fc36 15.08.2022 SB2022081549
SB2022081550
SB2022082552
and 6 more
#VU66507 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-28129
CWE-444 Medium
No
No
9.1.3-1.el7, 9.1.3-1.el8, 9.1.3-1.el9, 9.1.3-1.fc35, 9.1.3-1.fc36 15.08.2022 SB2022081549
SB2022081550
SB2022081141
and 4 more
#VU66506 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-25763
CWE-444 Medium
No
No
9.1.3-1.el7, 9.1.3-1.el8, 9.1.3-1.el9, 9.1.3-1.fc35, 9.1.3-1.fc36 15.08.2022 SB2022081549
SB2022081550
SB2022081141
and 4 more
#VU66504 - Improper Authorization
CVE-2021-37150
CWE-285 Medium
No
No
9.1.3-1.el7, 9.1.3-1.el8, 9.1.3-1.el9, 9.1.3-1.fc35, 9.1.3-1.fc36 15.08.2022 SB2022081549
SB2022081550
SB2022081141
and 4 more


Showing elements 41 - 60 out of 61