Known vulnerabilities in yarnpkg - page 2
Vendor:
Fedoraproject
Software:
yarnpkg
Software CPE:
cpe:2.3:o:fedoraproject:yarnpkg:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
28
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
1.22.22-18.fc44
1.22.22-18.el10_3
1.22.22-18.fc42
1.22.22-18.el9
1.22.22-18.fc43
1.22.22-17.fc43
1.22.22-17.fc44
1.22.22-17.el10_3
1.22.22-17.fc42
1.22.22-16.el10_2
1.22.22-16.el9
1.22.22-16.fc42
1.22.22-16.fc43
1.22.22-12.fc42
1.22.22-12.fc41
1.22.22-12.fc43
1.22.22-11.fc41
1.22.22-11.fc42
1.22.22-11.el9
1.22.22-11.el10_1
1.22.22-9.el8
1.22.22-9.fc41
1.22.22-9.el9
1.22.22-9.el10_1
1.22.22-9.fc42
1.22.22-8.el8
1.22.22-8.el10_1
1.22.22-8.fc42
1.22.22-8.fc41
1.22.22-8.el9
1.22.22-7.el8
1.22.22-7.fc42
1.22.22-7.fc40
1.22.22-7.fc41
1.22.22-7.el9
1.22.22-5.el9
1.22.22-5.fc39
1.22.22-5.fc41
1.22.22-5.fc40
1.22.22-4.fc39
1.22.22-4.fc41
1.22.22-4.fc40
1.22.22-2.fc40
1.22.21-2.fc39
1.22.21-2.fc38
1.22.19-5.el9
1.22.19-5.fc37
1.22.19-5.fc38
1.22.19-5.fc36
1.22.19-3.fc36
1.22.19-3.fc37
1.22.19-2.fc36
1.22.19-2.fc37
Vulnerabilities (28)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU92405 - Uncontrolled Memory Allocation CVE-2024-4068 |
CWE-789 | Medium | 1.22.22-5.el9 | 20.06.2024 |
SB20240620121 SB2024062833 SB2024070809 and 51 more |
||
| #VU72247 - Improper input validation CVE-2022-38900 |
CWE-20 | Medium | 1.22.19-5.el9, 1.22.19-5.fc36, 1.22.19-5.fc37, 1.22.19-5.fc38 | 15.02.2023 |
SB2023021531 SB2023022714 SB2023032315 and 35 more |
||
| #VU70122 - Incorrect Regular Expression CVE-2022-37599 |
CWE-185 | Medium | 1.22.21-2.fc38, 1.22.21-2.fc39 | 12.12.2022 |
SB2022121221 SB2023010424 SB2023020920 and 19 more |
||
| #VU70121 - Incorrect Regular Expression CVE-2022-37603 |
CWE-185 | Medium | 1.22.19-5.fc36, 1.22.19-5.fc37, 1.22.19-5.fc38 | 12.12.2022 |
SB2022121221 SB2022121222 SB2023010418 and 29 more |
||
| #VU69942 - Incorrect Regular Expression CVE-2022-3517 |
CWE-185 | Medium | 1.22.19-3.fc36, 1.22.19-3.fc37, 1.22.19-5.el9 | 06.12.2022 |
SB2022120638 SB2022120639 SB2022120640 and 50 more |
||
| #VU62361 - Improper Control of Generation of Code ('Code Injection') CVE-2021-43138 |
CWE-94 | Medium | 1.22.19-3.fc36, 1.22.19-3.fc37, 1.22.19-5.el9 | 15.04.2022 |
SB2022041532 SB2022041533 SB2022062103 and 33 more |
||
| #VU55102 - Resource exhaustion CVE-2021-35065 |
CWE-400 | Medium | 1.22.19-2.fc36, 1.22.19-2.fc37 | 21.07.2021 |
SB2021072101 SB2023020668 SB2023020971 and 24 more |
||
| #VU29230 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2020-7677 |
CWE-78 | High | 1.22.19-3.fc36, 1.22.19-3.fc37, 1.22.19-5.el9 | 24.06.2020 |
SB2020062410 SB2023041356 SB2023081657 and 2 more |
Showing elements 21 - 40 out of 28