Known vulnerabilities in cri-o (Red Hat package) - page 2

Software CPE: cpe:2.3:o:red_hat:cri-o_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 289
Public exploits: 18
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting cri-o (Red Hat package) cri-o (Red Hat package) is affected by 289 known vulnerabilities: 25 high, 168 medium, 96 low Critical High Medium Low

Vulnerabilities (289)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU103485 - Permissions, Privileges, and Access Controls
CVE-2024-8676
CWE-264 Low
No
No
1.28.11-7.rhaos4.15.gitc4c0556.el8, 1.28.11-7.rhaos4.15.gitc4c0556.el9 02.02.2025 SB2025020201
SB2025020338
SB2025031788
and 3 more
#VU101972 - Security Features
CVE-2024-56326
CWE-254 Low
No
No
1.29.12-4.rhaos4.16.gitadc9401.el8, 1.29.12-4.rhaos4.16.gitadc9401.el9, 1.30.9-3.rhaos4.17.gitbbf9018.el8, 1.30.9-3.rhaos4.17.gitbbf9018.el9 27.12.2024 SB2024122789
SB2024122790
SB2024122791
and 78 more
#VU101971 - Security Features
CVE-2024-56201
CWE-254 Low
No
No
1.29.12-4.rhaos4.16.gitadc9401.el8, 1.29.12-4.rhaos4.16.gitadc9401.el9, 1.30.9-3.rhaos4.17.gitbbf9018.el8, 1.30.9-3.rhaos4.17.gitbbf9018.el9 27.12.2024 SB2024122789
SB2025010203
SB2025010322
and 62 more
#VU98828 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-9675
CWE-22 Low
No
No
1.26.5-26.rhaos4.13.giteb3d487.el8, 1.26.5-26.rhaos4.13.giteb3d487.el9, 1.27.8-12.rhaos4.14.git7597c43.el8, 1.27.8-12.rhaos4.14.git7597c43.el9, 1.30.7-2.rhaos4.17.git2391edc.el8, 1.30.7-2.rhaos4.17.git2391edc.el9 21.10.2024 SB2024102103
SB2024102104
SB2024102107
and 51 more
#VU98817 - UNIX Symbolic Link (Symlink) Following
CVE-2024-9676
CWE-61 Low
No
No
1.25.5-5.rhaos4.12.git53dc492.el9, 1.25.5-30.rhaos4.12.git53dc492.el8, 1.26.5-26.rhaos4.13.giteb3d487.el8, 1.26.5-26.rhaos4.13.giteb3d487.el9, 1.27.8-12.rhaos4.14.git7597c43.el8, 1.27.8-12.rhaos4.14.git7597c43.el9, 1.28.11-5.rhaos4.15.git35a2431.el8, 1.28.11-5.rhaos4.15.git35a2431.el9, 1.29.9-6.rhaos4.16.gite7bd45a.el8, 1.29.9-6.rhaos4.16.gite7bd45a.el9, 1.30.6-6.rhaos4.17.git6ac6e96.el8, 1.30.6-6.rhaos4.17.git6ac6e96.el9, 1.30.7-2.rhaos4.17.git2391edc.el8, 1.30.7-2.rhaos4.17.git2391edc.el9 18.10.2024 SB2024101822
SB2024101823
SB2024101824
and 54 more
#VU98141 - Improper input validation
CVE-2024-9341
CWE-20 Low
No
No
1.25.5-5.rhaos4.12.git53dc492.el9, 1.25.5-30.rhaos4.12.git53dc492.el8, 1.26.5-26.rhaos4.13.giteb3d487.el8, 1.26.5-26.rhaos4.13.giteb3d487.el9, 1.27.8-10.rhaos4.14.git807f92c.el8, 1.27.8-10.rhaos4.14.git807f92c.el9, 1.28.11-5.rhaos4.15.git35a2431.el8, 1.28.11-5.rhaos4.15.git35a2431.el9, 1.29.9-5.rhaos4.16.git34690b9.el8, 1.29.9-5.rhaos4.16.git34690b9.el9, 1.30.6-3.rhaos4.17.git49b5172.el8, 1.30.6-3.rhaos4.17.git49b5172.el9 08.10.2024 SB2024100842
SB2024100843
SB2024100848
and 44 more
#VU97965 - Improper Access Control
CVE-2024-44082
CWE-284 Low
No
No
1.25.5-5.rhaos4.12.git53dc492.el9, 1.25.5-30.rhaos4.12.git53dc492.el8, 1.26.5-23.rhaos4.13.git6d9c688.el8, 1.26.5-23.rhaos4.13.git6d9c688.el9 02.10.2024 SB2024100260
SB2024100261
SB2024100262
and 10 more
#VU97217 - Resource exhaustion
CVE-2024-34158
CWE-400 Medium
No
No
1.25.5-5.rhaos4.12.git53dc492.el9, 1.25.5-30.rhaos4.12.git53dc492.el8, 1.26.5-26.rhaos4.13.giteb3d487.el8, 1.26.5-26.rhaos4.13.giteb3d487.el9, 1.27.8-12.rhaos4.14.git7597c43.el8, 1.27.8-12.rhaos4.14.git7597c43.el9, 1.28.11-5.rhaos4.15.git35a2431.el8, 1.28.11-5.rhaos4.15.git35a2431.el9, 1.29.9-5.rhaos4.16.git34690b9.el8, 1.29.9-5.rhaos4.16.git34690b9.el9, 1.30.6-5.rhaos4.17.git690d4d6.el8, 1.30.6-5.rhaos4.17.git690d4d6.el9 12.09.2024 SB2024091261
SB2024091264
SB2024091265
and 76 more
#VU97216 - Resource exhaustion
CVE-2024-34156
CWE-400 Medium
No
No
1.25.5-5.rhaos4.12.git53dc492.el9, 1.25.5-30.rhaos4.12.git53dc492.el8, 1.26.5-26.rhaos4.13.giteb3d487.el8, 1.26.5-26.rhaos4.13.giteb3d487.el9, 1.27.8-12.rhaos4.14.git7597c43.el8, 1.27.8-12.rhaos4.14.git7597c43.el9, 1.28.11-5.rhaos4.15.git35a2431.el8, 1.28.11-5.rhaos4.15.git35a2431.el9, 1.29.9-5.rhaos4.16.git34690b9.el8, 1.29.9-5.rhaos4.16.git34690b9.el9, 1.30.6-5.rhaos4.17.git690d4d6.el8, 1.30.6-5.rhaos4.17.git690d4d6.el9 12.09.2024 SB2024091261
SB2024091264
SB2024091265
and 143 more
#VU97215 - Resource exhaustion
CVE-2024-34155
CWE-400 Medium
No
No
1.25.5-5.rhaos4.12.git53dc492.el9, 1.25.5-30.rhaos4.12.git53dc492.el8, 1.26.5-26.rhaos4.13.giteb3d487.el8, 1.26.5-26.rhaos4.13.giteb3d487.el9, 1.27.8-12.rhaos4.14.git7597c43.el8, 1.27.8-12.rhaos4.14.git7597c43.el9, 1.28.11-5.rhaos4.15.git35a2431.el8, 1.28.11-5.rhaos4.15.git35a2431.el9, 1.29.9-5.rhaos4.16.git34690b9.el8, 1.29.9-5.rhaos4.16.git34690b9.el9, 1.30.6-5.rhaos4.17.git690d4d6.el8, 1.30.6-5.rhaos4.17.git690d4d6.el9 12.09.2024 SB2024091261
SB2024091264
SB2024091265
and 81 more
#VU96055 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2024-42353
CWE-601 Low
No
No
1.26.5-23.rhaos4.13.git6d9c688.el8, 1.26.5-23.rhaos4.13.git6d9c688.el9, 1.27.8-8.rhaos4.14.git17cbe6d.el8, 1.27.8-8.rhaos4.14.git17cbe6d.el9, 1.28.10-5.rhaos4.15.git7a788e6.el8, 1.28.10-5.rhaos4.15.git7a788e6.el9, 1.29.8-4.rhaos4.16.git7c340a9.el9 15.08.2024 SB2024081552
SB2024081555
SB2024081556
and 44 more
#VU94792 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2024-5569
CWE-835 Medium
No
No
1.29.9-6.rhaos4.16.gite7bd45a.el8, 1.29.9-6.rhaos4.16.gite7bd45a.el9, 1.30.6-5.rhaos4.17.git690d4d6.el8, 1.30.6-5.rhaos4.17.git690d4d6.el9 26.07.2024 SB2024072688
SB2024072690
SB2024072692
and 59 more
#VU94743 - Resource exhaustion
CVE-2024-37298
CWE-400 Medium
No
No
1.25.3-7.rhaos4.12.git44a2cb2.el9, 1.25.5-25.rhaos4.12.git6556f50.el8, 1.27.8-3.rhaos4.14.git107168f.el8, 1.27.8-3.rhaos4.14.git107168f.el9 25.07.2024 SB2024072523
SB2024072527
SB2024080127
and 13 more
#VU94616 - Information Exposure Through Log Files
CVE-2024-6104
CWE-532 Low
No
No
1.26.5-20.rhaos4.13.git2e90133.el8, 1.26.5-20.rhaos4.13.git2e90133.el9, 1.27.8-3.rhaos4.14.git107168f.el8, 1.27.8-3.rhaos4.14.git107168f.el9, 1.30.5-7.rhaos4.17.git2e89940.el8, 1.30.5-7.rhaos4.17.git2e89940.el9 19.07.2024 SB2024071927
SB2024071929
SB2024071930
and 83 more
#VU91160 - Improper input validation
CVE-2024-24790
CWE-20 Medium
No
No
1.25.3-7.rhaos4.12.git44a2cb2.el9, 1.25.5-25.rhaos4.12.git6556f50.el8, 1.26.5-20.rhaos4.13.git2e90133.el8, 1.26.5-20.rhaos4.13.git2e90133.el9, 1.27.8-5.rhaos4.14.git107168f.el8, 1.27.8-5.rhaos4.14.git107168f.el9, 1.28.9-5.rhaos4.15.git674ed4c.el8, 1.28.9-5.rhaos4.15.git674ed4c.el9, 1.29.9-6.rhaos4.16.gite7bd45a.el8, 1.29.9-6.rhaos4.16.gite7bd45a.el9 05.06.2024 SB2024060520
SB2024060635
SB2024060729
and 90 more
#VU91159 - Improper input validation
CVE-2024-24789
CWE-20 Low
No
No
1.30.5-7.rhaos4.17.git2e89940.el8, 1.30.5-7.rhaos4.17.git2e89940.el9 05.06.2024 SB2024060520
SB2024060635
SB2024060729
and 78 more
#VU89677 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-34064
CWE-79 Medium
No
No
1.26.5-21.rhaos4.13.git307b1ea.el8, 1.26.5-21.rhaos4.13.git307b1ea.el9, 1.28.8-3.rhaos4.15.gita511a66.el8 20.05.2024 SB2024052067
SB2024052081
SB2024052082
and 83 more
#VU89149 - Improper Control of Generation of Code ('Code Injection')
CVE-2024-34069
CWE-94 Medium
No
No
1.25.5-26.rhaos4.12.git635413a.el8 06.05.2024 SB2024050606
SB2024050723
SB2024050930
and 54 more
#VU87197 - Resource exhaustion
CVE-2023-45290
CWE-400 Medium
No
No
1.25.3-7.rhaos4.12.git44a2cb2.el9, 1.25.5-25.rhaos4.12.git6556f50.el8, 1.25.5-26.rhaos4.12.git635413a.el8, 1.26.5-20.rhaos4.13.git2e90133.el8, 1.26.5-20.rhaos4.13.git2e90133.el9, 1.27.8-5.rhaos4.14.git107168f.el8, 1.27.8-5.rhaos4.14.git107168f.el9, 1.28.9-5.rhaos4.15.git674ed4c.el8, 1.28.9-5.rhaos4.15.git674ed4c.el9, 1.29.5-5.rhaos4.16.git7032128.el8, 1.29.5-5.rhaos4.16.git7032128.el9 07.03.2024 SB2024030734
SB2024030750
SB2024030752
and 101 more
#VU83902 - Improper input validation
CVE-2023-45539
CWE-20 Medium
No
No
1.27.8-6.rhaos4.14.git06fccaa.el8, 1.27.8-6.rhaos4.14.git06fccaa.el9 06.12.2023 SB2023082120
SB2023120617
SB2023120620
and 21 more


Showing elements 21 - 40 out of 289