Known vulnerabilities in cri-o (Red Hat package) - page 13

Software CPE: cpe:2.3:o:red_hat:cri-o_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 289
Public exploits: 18
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting cri-o (Red Hat package) cri-o (Red Hat package) is affected by 289 known vulnerabilities: 25 high, 168 medium, 96 low Critical High Medium Low

Vulnerabilities (289)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU62797 - Improper Locking
CVE-2021-20291
CWE-667 Medium
No
No
1.20.2-6.rhaos4.7.gitf1d5201.el7, 1.20.2-6.rhaos4.7.gitf1d5201.el8 04.05.2022 SB2021040182
SB2022050417
SB2022092037
and 13 more
#VU52902 - Improper Validation of Array Index
CVE-2021-3121
CWE-129 High
No
No
1.20.2-4.rhaos4.7.gitd5a999a.el7, 1.20.2-4.rhaos4.7.gitd5a999a.el8, 1.21.2-5.rhaos4.8.gitb27d974.el7, 1.21.2-5.rhaos4.8.gitb27d974.el8 06.05.2021 SB2021011120
SB2021050602
SB2021050603
and 34 more
#VU52385 - Improper input validation
CVE-2020-27223
CWE-20 Medium
Available
No
1.19.2-6.rhaos4.6.git686e6d9.el7, 1.19.2-6.rhaos4.6.git686e6d9.el8 21.04.2021 SB2021042107
SB2021063002
SB2021063034
and 19 more
#VU51878 - Exposure of sensitive information to an unauthorized actor
CVE-2021-28163
CWE-200 Medium
No
No
1.20.2-11.rhaos4.7.git704b03d.el7, 1.20.2-11.rhaos4.7.git704b03d.el8 01.04.2021 SB2021040179
SB2021050704
SB2021051321
and 27 more
#VU51876 - Resource exhaustion
CVE-2021-28165
CWE-400 Medium
No
No
1.20.2-11.rhaos4.7.git704b03d.el7, 1.20.2-11.rhaos4.7.git704b03d.el8 01.04.2021 SB2021040179
SB2021042208
SB2021050704
and 56 more
#VU50047 - Incorrect Calculation
CVE-2021-3114
CWE-682 Medium
No
No
1.19.1-16.rhaos4.6.git130633b.el7, 1.19.1-16.rhaos4.6.git130633b.el8, 1.20.2-3.rhaos4.7.gitfecc319.el7, 1.20.2-3.rhaos4.7.gitfecc319.el8, 1.20.2-11.rhaos4.7.git704b03d.el7, 1.20.2-11.rhaos4.7.git704b03d.el8, 1.21.2-5.rhaos4.8.gitb27d974.el7, 1.21.2-5.rhaos4.8.gitb27d974.el8 26.01.2021 SB2021012714
SB2021012715
SB20210120130
and 40 more
#VU49524 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21610
CWE-79 Low
No
No
1.19.1-7.rhaos4.6.git6377f68.el7 14.01.2021 SB2021011418
SB2021011452
SB2021012106
and 2 more
#VU49523 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21608
CWE-79 Low
No
No
1.19.1-7.rhaos4.6.git6377f68.el7 14.01.2021 SB2021011418
SB2021011450
SB2021012106
and 2 more
#VU49522 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21603
CWE-79 Low
No
No
1.19.1-7.rhaos4.6.git6377f68.el7 13.01.2021 SB2021011418
SB2021011445
SB2021012106
and 2 more
#VU49526 - XML Injection
CVE-2021-21604
CWE-91 Medium
No
No
1.19.1-7.rhaos4.6.git6377f68.el7 13.01.2021 SB2021011418
SB2021011446
SB2021012106
and 2 more
#VU49527 - Exposure of sensitive information to an unauthorized actor
CVE-2021-21602
CWE-200 Medium
No
No
1.19.1-7.rhaos4.6.git6377f68.el7 13.01.2021 SB2021011418
SB2021011444
SB2021012106
and 2 more
#VU49528 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-21605
CWE-22 Medium
No
No
1.19.1-7.rhaos4.6.git6377f68.el7 13.01.2021 SB2021011418
SB2021011447
SB2021012106
and 2 more
#VU49529 - Permissions, Privileges, and Access Controls
CVE-2021-21606
CWE-264 Low
No
No
1.19.1-7.rhaos4.6.git6377f68.el7 13.01.2021 SB2021011418
SB2021011448
SB2021012106
and 2 more
#VU49530 - Memory corruption
CVE-2021-21607
CWE-119 Medium
No
No
1.19.1-7.rhaos4.6.git6377f68.el7 13.01.2021 SB2021011418
SB2021011449
SB2021012106
and 2 more
#VU49531 - Permissions, Privileges, and Access Controls
CVE-2021-21609
CWE-264 Low
No
No
1.19.1-7.rhaos4.6.git6377f68.el7 13.01.2021 SB2021011418
SB2021011451
SB2021012106
and 2 more
#VU48480 - Improper input validation
CVE-2020-28362
CWE-20 Medium
No
No
1.20.2-11.rhaos4.7.git704b03d.el7, 1.20.2-11.rhaos4.7.git704b03d.el8 17.11.2020 SB2020111715
SB2020111716
SB2020111225
and 30 more
#VU45699 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-16845
CWE-835 Medium
No
No
1.18.3-19.rhaos4.5.git9264b4f.el7, 1.18.3-19.rhaos4.5.git9264b4f.el8, 1.18.4-4.rhaos4.5.git6dee389.el7, 1.18.4-4.rhaos4.5.git6dee389.el8, 1.18.4-7.rhaos4.5.git572d9f7.el7, 1.18.4-7.rhaos4.5.git572d9f7.el8, 1.20.2-12.rhaos4.7.git9f7be76.el7, 1.20.2-12.rhaos4.7.git9f7be76.el8 14.08.2020 SB2020081403
SB2020081404
SB2020081405
and 44 more
#VU31891 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2020-15586
CWE-362 Medium
No
No
1.18.3-19.rhaos4.5.git9264b4f.el7, 1.18.3-19.rhaos4.5.git9264b4f.el8, 1.18.4-4.rhaos4.5.git6dee389.el7, 1.18.4-4.rhaos4.5.git6dee389.el8, 1.18.4-7.rhaos4.5.git572d9f7.el7, 1.18.4-7.rhaos4.5.git572d9f7.el8, 1.20.2-12.rhaos4.7.git9f7be76.el7, 1.20.2-12.rhaos4.7.git9f7be76.el8 27.07.2020 SB2020072734
SB2020072735
SB2020072749
and 37 more
#VU27924 - Incorrect Default Permissions
CVE-2020-1945
CWE-276 Low
No
No
1.19.1-7.rhaos4.6.git6377f68.el7 15.05.2020 SB2020051501
SB2020052114
SB2020060205
and 48 more
#VU47428 - Permissions, Privileges, and Access Controls
CVE-2020-11979
CWE-264 Low
No
No
1.19.1-7.rhaos4.6.git6377f68.el7 14.05.2020 SB2020100804
SB2020100815
SB2020111614
and 51 more


Showing elements 241 - 260 out of 289