Known vulnerabilities in conmon (Red Hat package) - page 5
Vendor:
Red Hat Inc.
Software:
conmon (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:conmon_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
108
Public exploits:
5
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2.1.12-12.rhaos4.19.el9
2.1.12-12.rhaos4.20.el9
2.1.12-10.rhaos4.18.el8
2.1.12-8.rhaos4.17.el8
2.1.12-8.rhaos4.17.el9
2.1.12-11.rhaos4.21.el9
2.1.12-1.rhaos4.18.el8
2.1.7-6.rhaos4.14.el8
2.1.7-6.rhaos4.14.el9
2.1.2-8.rhaos4.12.el8
2.1.2-9.rhaos4.12.el9
2.1.7-5.rhaos4.13.el8
2.1.7-5.rhaos4.13.el9
2.1.7-10.rhaos4.15.el8
2.1.7-15.rhaos4.15.el9
2.1.10-5.rhaos4.16.el8
2.1.10-5.rhaos4.16.el9
2.1.12-5.rhaos4.17.el8
2.1.12-5.rhaos4.17.el9
2.1.12-4.rhaos4.17.el8
2.1.12-4.rhaos4.17.el9
2.1.7-9.rhaos4.15.el8
2.1.7-14.rhaos4.15.el9
2.1.7-4.rhaos4.13.el8
2.1.7-4.rhaos4.13.el9
2.1.7-5.rhaos4.14.el8
2.1.7-5.rhaos4.14.el9
2.1.2-7.rhaos4.12.el8
2.1.2-8.rhaos4.12.el9
2.1.10-2.1.rhaos4.16.el8
2.1.10-2.1.rhaos4.16.el9
2.1.7-2.3.rhaos4.13.el8
2.1.7-2.3.rhaos4.13.el9
2.1.7-6.rhaos4.15.el8
2.1.7-11.2.rhaos4.15.el9
2.1.7-10.2.rhaos4.15.el9
2.1.2-5.3.rhaos4.12.el8
2.1.2-6.3.rhaos4.12.el9
2.1.7-2.2.rhaos4.13.el8
2.1.7-2.2.rhaos4.13.el9
2.1.7-3.3.rhaos4.14.el8
2.1.7-3.3.rhaos4.14.el9
2.1.2-5.2.rhaos4.12.el8
2.1.2-6.2.rhaos4.12.el9
2.1.7-10.1.rhaos4.15.el9
2.1.7-1.2.rhaos4.14.el9
2.1.2-4.1.rhaos4.11.el8
2.1.2-6.1.rhaos4.12.el9
2.1.7-3.1.rhaos4.14.el8
2.1.7-3.1.rhaos4.14.el9
2.1.2-3.rhaos4.11.el8
2.1.2-4.rhaos4.12.el8
2.1.2-5.rhaos4.12.el9
2.1.7-2.rhaos4.13.el8
2.1.7-2.1.rhaos4.13.el9
2.1.7-1.1.rhaos4.13.el9
2.1.7-1.rhaos4.13.el8
2.1.7-1.rhaos4.13.el9
2.1.7-1.el9_2
2.1.2-3.rhaos4.12.el8
2.1.2-4.rhaos4.12.el9
2.0.21-2.rhaos4.6.el7
2.0.21-2.rhaos4.6.el8
2.1.2-3.rhaos4.12.el9
2.1.2-2.rhaos4.11.el8
2.0.21-3.rhaos4.6.el7
2.0.21-3.rhaos4.6.el8
2.0.29-3.rhaos4.8.el7
2.0.29-3.rhaos4.8.el8
2.0.29-3.rhaos4.7.el7
2.0.29-3.rhaos4.7.el8
2.0.29-3.rhaos4.9.el7
2.0.29-3.rhaos4.9.el8
2.0.29-3.rhaos4.10.el8
2.0.21-1.rhaos4.5.el7
2.0.21-1.rhaos4.5.el8
2.0.8-3.rhaos4.3.el7
2.0.9-3.rhaos4.3.el8
2.0.17-1.rhaos4.3.el7
2.0.17-1.rhaos4.3.el8
2.0.17-1.rhaos4.4.el7
2.0.17-1.rhaos4.4.el8
2.0.9-1.el8
2.0.8-2.el7
Vulnerabilities (108)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU64008 - Resource exhaustion CVE-2022-1708 |
CWE-400 | Medium | 2.0.21-3.rhaos4.6.el7, 2.0.21-3.rhaos4.6.el8, 2.0.29-3.rhaos4.7.el7, 2.0.29-3.rhaos4.7.el8, 2.0.29-3.rhaos4.8.el7, 2.0.29-3.rhaos4.8.el8, 2.0.29-3.rhaos4.9.el7, 2.0.29-3.rhaos4.9.el8, 2.0.29-3.rhaos4.10.el8 | 07.06.2022 |
SB2022060707 SB2022061334 SB2022061627 and 15 more |
||
| #VU63493 - Improper Access Control CVE-2022-1706 |
CWE-284 | Low | 2.1.2-2.rhaos4.11.el8 | 20.05.2022 |
SB2022052015 SB2022071162 SB2022071163 and 9 more |
||
| #VU63090 - Permissions, Privileges, and Access Controls CVE-2022-29162 |
CWE-264 | Medium | 2.1.2-2.rhaos4.11.el8 | 12.05.2022 |
SB2022051205 SB2022062435 SB2022071158 and 32 more |
||
| #VU62304 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2022-29046 |
CWE-79 | Low | 2.0.21-3.rhaos4.6.el7, 2.0.21-3.rhaos4.6.el8 | 13.04.2022 |
SB2022041333 SB2022053122 SB2022061218 and 3 more |
||
| #VU62292 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2022-29036 |
CWE-79 | Low | 2.0.21-3.rhaos4.6.el7, 2.0.21-3.rhaos4.6.el8 | 13.04.2022 |
SB2022041321 SB2022053122 SB2022061218 and 2 more |
||
| #VU62039 - Use of a Broken or Risky Cryptographic Algorithm CVE-2022-27191 |
CWE-327 | Medium | 2.1.2-2.rhaos4.11.el8 | 10.04.2022 |
SB2022041004 SB2022041406 SB2022081226 and 91 more |
||
| #VU62037 - Incorrect Authorization CVE-2022-23773 |
CWE-863 | Low | 2.1.2-2.rhaos4.11.el8 | 10.04.2022 |
SB2022041002 SB2022060126 SB2022060127 and 39 more |
||
| #VU62036 - Unchecked Return Value CVE-2022-23806 |
CWE-252 | Medium | 2.1.2-2.rhaos4.11.el8 | 10.04.2022 |
SB2022041002 SB2022041003 SB2022060126 and 46 more |
||
| #VU61599 - Improper input validation CVE-2022-21698 |
CWE-20 | Medium | 2.1.2-2.rhaos4.11.el8 | 24.03.2022 |
SB2022021530 SB2022032413 SB2022040807 and 110 more |
||
| #VU61227 - Incorrect Regular Expression CVE-2022-24921 |
CWE-185 | Medium | 2.1.2-2.rhaos4.11.el8 | 10.03.2022 |
SB2022031004 SB2022031005 SB2022041208 and 41 more |
||
| #VU49523 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2021-21608 |
CWE-79 | Low | 2.0.21-1.rhaos4.5.el7, 2.0.21-1.rhaos4.5.el8 | 14.01.2021 |
SB2021011418 SB2021011450 SB2021012106 and 2 more |
||
| #VU49522 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2021-21603 |
CWE-79 | Low | 2.0.21-1.rhaos4.5.el7, 2.0.21-1.rhaos4.5.el8 | 13.01.2021 |
SB2021011418 SB2021011445 SB2021012106 and 2 more |
||
| #VU49526 - XML Injection CVE-2021-21604 |
CWE-91 | Medium | 2.0.21-1.rhaos4.5.el7, 2.0.21-1.rhaos4.5.el8 | 13.01.2021 |
SB2021011418 SB2021011446 SB2021012106 and 2 more |
||
| #VU49527 - Exposure of sensitive information to an unauthorized actor CVE-2021-21602 |
CWE-200 | Medium | 2.0.21-1.rhaos4.5.el7, 2.0.21-1.rhaos4.5.el8 | 13.01.2021 |
SB2021011418 SB2021011444 SB2021012106 and 2 more |
||
| #VU49528 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2021-21605 |
CWE-22 | Medium | 2.0.21-1.rhaos4.5.el7, 2.0.21-1.rhaos4.5.el8 | 13.01.2021 |
SB2021011418 SB2021011447 SB2021012106 and 2 more |
||
| #VU49529 - Permissions, Privileges, and Access Controls CVE-2021-21606 |
CWE-264 | Low | 2.0.21-1.rhaos4.5.el7, 2.0.21-1.rhaos4.5.el8 | 13.01.2021 |
SB2021011418 SB2021011448 SB2021012106 and 2 more |
||
| #VU49530 - Memory corruption CVE-2021-21607 |
CWE-119 | Medium | 2.0.21-1.rhaos4.5.el7, 2.0.21-1.rhaos4.5.el8 | 13.01.2021 |
SB2021011418 SB2021011449 SB2021012106 and 2 more |
||
| #VU49531 - Permissions, Privileges, and Access Controls CVE-2021-21609 |
CWE-264 | Low | 2.0.21-1.rhaos4.5.el7, 2.0.21-1.rhaos4.5.el8 | 13.01.2021 |
SB2021011418 SB2021011451 SB2021012106 and 2 more |
||
| #VU27924 - Incorrect Default Permissions CVE-2020-1945 |
CWE-276 | Low | 2.0.21-1.rhaos4.5.el7, 2.0.21-1.rhaos4.5.el8 | 15.05.2020 |
SB2020051501 SB2020052114 SB2020060205 and 48 more |
||
| #VU47428 - Permissions, Privileges, and Access Controls CVE-2020-11979 |
CWE-264 | Low | 2.0.21-1.rhaos4.5.el7, 2.0.21-1.rhaos4.5.el8 | 14.05.2020 |
SB2020100804 SB2020100815 SB2020111614 and 51 more |
Showing elements 81 - 100 out of 108