Known vulnerabilities in rpm-help

Vendor: openEuler
Software: rpm-help
Software CPE: cpe:2.3:o:openeuler:rpm-help:*:*:*:*:*:openeuler:*:*
Total vulnerabilities: 9
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting rpm-help rpm-help is affected by 9 known vulnerabilities: 3 medium, 6 low Critical High Medium Low

Vulnerabilities (9)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU79523 - Improper Link Resolution Before File Access ('Link Following')
CVE-2021-35939
CWE-59 Low
No
No
4.15.1-28 15.08.2023 SB2023081530
SB2024012452
SB2024012458
and 45 more
#VU79522 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2021-35937
CWE-367 Low
No
No
4.15.1-28 15.08.2023 SB2023081530
SB2024012452
SB2024012458
and 45 more
#VU79521 - Improper Link Resolution Before File Access ('Link Following')
CVE-2021-35938
CWE-59 Low
No
No
4.15.1-28 15.08.2023 SB2023081530
SB2024012452
SB2024012458
and 45 more
#VU59993 - Improper Verification of Cryptographic Signature
CVE-2021-3521
CWE-347 Medium
No
No
4.15.1-26 25.01.2022 SB2022012518
SB2022012519
SB2022020935
and 23 more
#VU54479 - Improper Verification of Cryptographic Signature
CVE-2021-3421
CWE-347 Medium
No
No
4.15.1-24 30.06.2021 SB2021063036
SB2021071302
SB2021072003
and 15 more
#VU54478 - Out-of-bounds read
CVE-2021-20266
CWE-125 Low
No
No
4.15.1-24 30.06.2021 SB2021063035
SB2021072003
SB2021111133
and 16 more
#VU54477 - Insufficient Verification of Data Authenticity
CVE-2021-20271
CWE-345 Medium
No
No
4.15.1-20 30.06.2021 SB2021063035
SB2021063038
SB2021071302
and 34 more
#VU31245 - Improper Link Resolution Before File Access ('Link Following')
CVE-2017-7500
CWE-59 Low
No
No
4.15.1-28 13.08.2018 SB2018081318
SB2018102434
SB2018080623
and 14 more
#VU31396 - Improper Link Resolution Before File Access ('Link Following')
CVE-2017-7501
CWE-59 Low
No
No
4.15.1-28 22.11.2017 SB2017112213
SB2018102434
SB2022110933
and 13 more