Known vulnerabilities in cri-o (Red Hat package) - page 14

Software CPE: cpe:2.3:o:red_hat:cri-o_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 289
Public exploits: 18
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting cri-o (Red Hat package) cri-o (Red Hat package) is affected by 289 known vulnerabilities: 25 high, 168 medium, 96 low Critical High Medium Low

Vulnerabilities (289)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU69447 - Reachable Assertion
CVE-2020-9283
CWE-617 Medium
Available
No
1.16.6-18.rhaos4.3.git538d861.el7, 1.16.6-18.rhaos4.3.git538d861.el8 21.11.2022 SB2020022039
SB2022112104
SB2023090418
and 6 more
#VU50020 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2021-21615
CWE-367 Medium
No
No
1.19.1-7.rhaos4.6.git6377f68.el7 26.01.2021 SB2021012623
SB2021021723
SB2021022601
and 1 more
#VU49525 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21611
CWE-79 Low
No
No
1.19.1-7.rhaos4.6.git6377f68.el7 14.01.2021 SB2021011418
SB2021011453
SB2021012106
and 2 more
#VU48976 - Information Exposure Through Log Files
CVE-2020-8563
CWE-532 Low
No
No
1.19.0-26.rhaos4.6.git8a05a29.el8 07.12.2020 SB2020121507
SB2020121508
SB2020121509
#VU48977 - Information Exposure Through Log Files
CVE-2020-8564
CWE-532 Low
No
No
1.11.16-0.16.rhaos3.11.git54f9e69.el7, 1.19.1-4.rhaos4.6.git3846aab.el8 07.12.2020 SB2020121507
SB2020121509
SB2020121808
and 6 more
#VU30129 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-2223
CWE-79 Low
No
No
1.17.4-24.rhaos4.4.git73658e6.el7, 1.17.4-24.rhaos4.4.git73658e6.el8 16.07.2020 SB20200716112
SB2020082409
SB2020071911
and 2 more
#VU30128 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-2222
CWE-79 Low
No
No
1.17.4-24.rhaos4.4.git73658e6.el7, 1.17.4-24.rhaos4.4.git73658e6.el8 16.07.2020 SB20200716112
SB2020082409
SB2020071910
and 2 more
#VU30127 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-2221
CWE-79 Low
No
No
1.17.4-24.rhaos4.4.git73658e6.el7, 1.17.4-24.rhaos4.4.git73658e6.el8 16.07.2020 SB20200716112
SB2020082409
SB2020071909
and 2 more
#VU30126 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-2220
CWE-79 Low
No
No
1.17.4-24.rhaos4.4.git73658e6.el7, 1.17.4-24.rhaos4.4.git73658e6.el8 16.07.2020 SB20200716112
SB2020082409
SB2020071908
and 2 more
#VU26514 - Resource exhaustion
CVE-2020-1702
CWE-400 Medium
No
No
1.11.16-0.9.dev.rhaos3.11.git6d43aae.el7, 1.17.4-8.dev.rhaos4.4.git5f5c5e4.el7, 1.17.4-8.dev.rhaos4.4.git5f5c5e4.el8 01.04.2020 SB2020040142
SB2020040143
SB2020040149
and 7 more
#VU26474 - Uncontrolled Memory Allocation
CVE-2020-8552
CWE-789 Medium
No
No
1.16.3-26.dev.rhaos4.3.git9aad8e4.el7, 1.16.3-28.dev.rhaos4.3.git9aad8e4.el8 31.03.2020 SB2020033111
SB2020040174
SB2020042251
and 6 more
#VU26393 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-2163
CWE-79 Low
No
No
1.16.6-15.dev.rhaos4.3.gitebc053b.el7, 1.16.6-15.dev.rhaos4.3.gitebc053b.el8, 1.17.4-14.dev.rhaos4.4.gitb93af5d.el7, 1.17.4-14.dev.rhaos4.4.gitb93af5d.el8 26.03.2020 SB2020032622
SB2020032668
SB2020061738
and 1 more
#VU26392 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-2162
CWE-79 Low
No
No
1.16.6-15.dev.rhaos4.3.gitebc053b.el7, 1.16.6-15.dev.rhaos4.3.gitebc053b.el8, 1.17.4-14.dev.rhaos4.4.gitb93af5d.el7, 1.17.4-14.dev.rhaos4.4.gitb93af5d.el8 26.03.2020 SB2020032622
SB2020032667
SB2020061738
and 1 more
#VU26391 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-2161
CWE-79 Low
No
No
1.16.6-15.dev.rhaos4.3.gitebc053b.el7, 1.16.6-15.dev.rhaos4.3.gitebc053b.el8, 1.17.4-14.dev.rhaos4.4.gitb93af5d.el7, 1.17.4-14.dev.rhaos4.4.gitb93af5d.el8 26.03.2020 SB2020032622
SB2020032662
SB2020061738
and 1 more
#VU26390 - Cross-Site Request Forgery (CSRF)
CVE-2020-2160
CWE-352 Low
No
No
1.16.6-15.dev.rhaos4.3.gitebc053b.el7, 1.16.6-15.dev.rhaos4.3.gitebc053b.el8, 1.17.4-14.dev.rhaos4.4.gitb93af5d.el7, 1.17.4-14.dev.rhaos4.4.gitb93af5d.el8 26.03.2020 SB2020032622
SB2020032661
SB2020061738
and 1 more
#VU25501 - Use After Free
CVE-2020-8945
CWE-416 High
No
No
1.16.4-1.dev.rhaos4.3.git9238eee.el7, 1.16.4-1.dev.rhaos4.3.git9238eee.el8, 1.17.4-8.dev.rhaos4.4.git5f5c5e4.el7, 1.17.4-8.dev.rhaos4.4.git5f5c5e4.el8 21.02.2020 SB2020022110
SB2020031116
SB2020031126
and 23 more
#VU24761 - Cryptographic Issues
CVE-2020-2102
CWE-310 Medium
No
No
1.16.3-22.dev.rhaos4.3.git11c04e3.el8 30.01.2020 SB2020013005
SB20200310153
#VU24760 - Exposure of sensitive information to an unauthorized actor
CVE-2020-2101
CWE-200 Medium
No
No
1.16.3-22.dev.rhaos4.3.git11c04e3.el8 30.01.2020 SB2020013005
SB20200310153
#VU24759 - Resource Management Errors
CVE-2020-2100
CWE-399 Medium
No
No
1.16.3-22.dev.rhaos4.3.git11c04e3.el8 30.01.2020 SB2020013005
SB20200310153
#VU24758 - Improper Authentication
CVE-2020-2099
CWE-287 High
No
No
1.16.3-22.dev.rhaos4.3.git11c04e3.el8 30.01.2020 SB2020013004
SB20200310153


Showing elements 261 - 280 out of 289