Known vulnerabilities in buildah (Red Hat package) - page 6

Software CPE: cpe:2.3:o:red_hat:buildah_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 128
Public exploits: 5
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting buildah (Red Hat package) buildah (Red Hat package) is affected by 128 known vulnerabilities: 8 high, 88 medium, 32 low Critical High Medium Low

Vulnerabilities (128)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU77628 - Improper input validation
CVE-2012-6153
CWE-20 Medium
No
No
1.19.7-1.el8 22.06.2023 SB2023062250
SB2023092013
SB2023092037
and 15 more
#VU69291 - Incorrect Authorization
CVE-2022-2990
CWE-863 Low
No
No
1.27.0-2.el9, 1.29.1-1.rhaos4.13.el9 14.11.2022 SB2022111431
SB2022111435
SB2022111439
and 14 more
#VU68299 - Incorrect Permission Assignment for Critical Resource
CVE-2022-0532
CWE-732 Medium
No
No
1.19.7-1.el8 13.10.2022 SB2022101333
SB2022101334
SB2022101335
and 4 more
#VU63493 - Improper Access Control
CVE-2022-1706
CWE-284 Low
No
No
1.23.4-2.el8 20.05.2022 SB2022052015
SB2022071162
SB2022071163
and 9 more
#VU63090 - Permissions, Privileges, and Access Controls
CVE-2022-29162
CWE-264 Medium
No
No
1.23.4-2.el8 12.05.2022 SB2022051205
SB2022062435
SB2022071158
and 32 more
#VU62039 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2022-27191
CWE-327 Medium
No
No
1.23.4-2.el8, 1.27.0-2.el9 10.04.2022 SB2022041004
SB2022041406
SB2022081226
and 91 more
#VU62037 - Incorrect Authorization
CVE-2022-23773
CWE-863 Low
Available
No
1.23.4-2.el8 10.04.2022 SB2022041002
SB2022060126
SB2022060127
and 39 more
#VU62036 - Unchecked Return Value
CVE-2022-23806
CWE-252 Medium
No
No
1.23.4-2.el8 10.04.2022 SB2022041002
SB2022041003
SB2022060126
and 46 more
#VU61599 - Improper input validation
CVE-2022-21698
CWE-20 Medium
No
No
1.23.4-2.el8 24.03.2022 SB2022021530
SB2022032413
SB2022040807
and 110 more
#VU61227 - Incorrect Regular Expression
CVE-2022-24921
CWE-185 Medium
No
No
1.23.4-2.el8 10.03.2022 SB2022031004
SB2022031005
SB2022041208
and 41 more
#VU59042 - Resource exhaustion
CVE-2021-44717
CWE-400 Medium
No
No
1.19.7-1.el8 16.12.2021 SB2021121610
SB2021121646
SB2022031628
and 32 more
#VU58824 - Improper input validation
CVE-2021-44716
CWE-20 Medium
No
No
1.19.7-1.el8 10.12.2021 SB2021121010
SB2021121011
SB2021121605
and 67 more
#VU58229 - Type confusion
CVE-2021-41190
CWE-843 Low
No
No
1.19.7-1.el8 18.11.2021 SB2021111806
SB2021111807
SB2021111809
and 39 more
#VU57150 - Improper Certificate Validation
CVE-2014-3577
CWE-295 Low
No
No
1.19.7-1.el8 08.10.2021 SB2014082106
SB2021100807
SB2023020872
and 24 more
#VU57149 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21684
CWE-79 Low
No
No
1.19.7-1.el8 08.10.2021 SB2021100806
SB2023022165
SB2022031044
and 1 more
#VU45699 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-16845
CWE-835 Medium
No
No
1.11.6-9.rhaos4.5.el8 14.08.2020 SB2020081403
SB2020081404
SB2020081405
and 44 more
#VU31891 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2020-15586
CWE-362 Medium
No
No
1.11.6-9.rhaos4.5.el8 27.07.2020 SB2020072734
SB2020072735
SB2020072749
and 37 more
#VU34248 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-14040
CWE-835 Medium
No
No
1.11.6-12.el7_9 17.06.2020 SB2020061731
SB2020100906
SB2020102814
and 25 more
#VU26643 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2020-10696
CWE-22 High
No
No
1.11.6-11.el7_8 07.04.2020 SB2020040723
SB2020042905
SB2020043013
and 12 more
#VU26514 - Resource exhaustion
CVE-2020-1702
CWE-400 Medium
No
No
1.11.6-11.el7_8 01.04.2020 SB2020040142
SB2020040143
SB2020040149
and 7 more


Showing elements 101 - 120 out of 128