Known vulnerabilities in crun (Red Hat package) - page 3
Vendor:
Red Hat Inc.
Software:
crun (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:crun_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
76
Public exploits:
5
Known exploited (KEV):
1
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
1.27-1.el9_6
1.14.3-1.el9_0
1.27-1.el10_1
1.27-1.el9_7
1.20-4.rhaos4.18.el8
1.20-2.rhaos4.18.el9
1.17-2.rhaos4.15.el8
1.17-2.rhaos4.15.el9
1.17-2.rhaos4.16.el8
1.17-2.rhaos4.16.el9
1.17-2.rhaos4.14.el8
1.17-2.rhaos4.14.el9
1.19.1-1.rhaos4.17.el8
1.17-1.rhaos4.17.el8
1.17-1.rhaos4.17.el9
1.14.3-2.rhaos4.17.el8
1.14.3-2.rhaos4.17.el9
1.17-1.rhaos4.14.el8
1.17-1.rhaos4.14.el9
1.17-1.rhaos4.16.el8
1.17-1.rhaos4.16.el9
1.14.3-1.rhaos4.16.el8
1.14.3-1.rhaos4.16.el9
1.14-1.rhaos4.15.el9
1.14-1.rhaos4.13.el8
1.14-1.rhaos4.13.el9
1.14-1.rhaos4.14.el8
1.14-1.rhaos4.14.el9
1.9.2-1.rhaos4.14.el8
1.9.2-1.rhaos4.14.el9
1.9.2-1.rhaos4.13.el8
1.9.2-1.rhaos4.13.el9
1.8.4-1.rhaos4.13.el9
1.4.2-2.rhaos4.12.el8
1.4.2-3.rhaos4.12.el9
1.4.2-2.rhaos4.12.el9
1.4.2-1.rhaos4.11.el8
1.4.2-1.rhaos4.10.el8
Vulnerabilities (76)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU82064 - Resource exhaustion CVE-2023-39325 |
CWE-400 | Medium | 1.9.2-1.rhaos4.13.el8, 1.9.2-1.rhaos4.13.el9, 1.9.2-1.rhaos4.14.el8, 1.9.2-1.rhaos4.14.el9, 1.14-1.rhaos4.15.el9 | 16.10.2023 |
SB2023101651 SB2023101652 SB2023101653 and 341 more |
||
| #VU81728 - Resource exhaustion CVE-2023-44487 |
CWE-400 | High | 1.9.2-1.rhaos4.13.el8, 1.9.2-1.rhaos4.13.el9, 1.9.2-1.rhaos4.14.el8, 1.9.2-1.rhaos4.14.el9, 1.14-1.rhaos4.15.el9 | 10.10.2023 |
SB2023101023 SB2023101024 SB2023101037 and 650 more |
||
| #VU80575 - Improper input validation CVE-2023-39322 |
CWE-20 | Medium | 1.9.2-1.rhaos4.14.el8, 1.9.2-1.rhaos4.14.el9 | 08.09.2023 |
SB2023090845 SB2023091875 SB2023091876 and 51 more |
||
| #VU80574 - Improper input validation CVE-2023-39321 |
CWE-20 | Medium | 1.9.2-1.rhaos4.14.el8, 1.9.2-1.rhaos4.14.el9 | 08.09.2023 |
SB2023090845 SB2023091875 SB2023091876 and 52 more |
||
| #VU80573 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-39319 |
CWE-79 | Medium | 1.9.2-1.rhaos4.14.el8, 1.9.2-1.rhaos4.14.el9 | 08.09.2023 |
SB2023090845 SB2023091146 SB2023091875 and 62 more |
||
| #VU74843 - Time-of-check Time-of-use (TOCTOU) Race Condition CVE-2023-0778 |
CWE-367 | Medium | 1.8.4-1.rhaos4.13.el9 | 11.04.2023 |
SB2023041130 SB2023041131 SB2023051738 and 10 more |
||
| #VU74481 - Improper Access Control CVE-2023-0229 |
CWE-284 | Low | 1.8.4-1.rhaos4.13.el9 | 05.04.2023 |
SB2023040518 SB2023040543 SB2023051810 and 3 more |
||
| #VU73722 - Resource exhaustion CVE-2022-41725 |
CWE-400 | Medium | 1.8.4-1.rhaos4.13.el9 | 15.03.2023 |
SB2023030130 SB2023031537 SB2023031538 and 80 more |
||
| #VU72685 - Resource Management Errors CVE-2022-41724 |
CWE-399 | Medium | 1.8.4-1.rhaos4.13.el9 | 01.03.2023 |
SB2023030130 SB2023030131 SB2023030211 and 87 more |
||
| #VU72339 - Resource exhaustion CVE-2023-25577 |
CWE-400 | Medium | 1.8.4-1.rhaos4.13.el9 | 16.02.2023 |
SB2023021673 SB2023022875 SB2023031332 and 49 more |
||
| #VU72334 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2023-25725 |
CWE-444 | Medium | 1.8.4-1.rhaos4.13.el9 | 16.02.2023 |
SB2023021659 SB2023021662 SB2023021663 and 22 more |
||
| #VU71431 - Improper input validation CVE-2023-0056 |
CWE-20 | Medium | 1.8.4-1.rhaos4.13.el9 | 23.01.2023 |
SB2023012331 SB2023012332 SB2023012641 and 20 more |
||
| #VU71362 - Protection Mechanism Failure CVE-2022-3259 |
CWE-693 | Low | 1.8.4-1.rhaos4.13.el9 | 19.01.2023 |
SB2023011939 SB2023020908 SB2023032315 and 8 more |
||
| #VU70334 - Allocation of Resources Without Limits or Throttling CVE-2022-41717 |
CWE-770 | Medium | 1.8.4-1.rhaos4.13.el9 | 14.12.2022 |
SB2022121432 SB2022121433 SB2022121435 and 185 more |
||
| #VU69291 - Incorrect Authorization CVE-2022-2990 |
CWE-863 | Low | 1.8.4-1.rhaos4.13.el9 | 14.11.2022 |
SB2022111431 SB2022111435 SB2022111439 and 14 more |
||
| #VU68390 - Resource exhaustion CVE-2022-41715 |
CWE-400 | Medium | 1.4.2-2.rhaos4.12.el8, 1.4.2-3.rhaos4.12.el9 | 18.10.2022 |
SB2022101833 SB2022101834 SB2022102005 and 113 more |
||
| #VU68389 - Improper input validation CVE-2022-2880 |
CWE-20 | Medium | 1.4.2-2.rhaos4.12.el8, 1.4.2-3.rhaos4.12.el9 | 18.10.2022 |
SB2022101833 SB2022101834 SB2022102005 and 94 more |
||
| #VU68387 - Resource Management Errors CVE-2022-2879 |
CWE-399 | Medium | 1.4.2-2.rhaos4.12.el8, 1.4.2-3.rhaos4.12.el9 | 18.10.2022 |
SB2022101833 SB2022101834 SB2022102005 and 78 more |
||
| #VU67396 - Improper input validation CVE-2022-27664 |
CWE-20 | Medium | 1.9.2-1.rhaos4.14.el8, 1.9.2-1.rhaos4.14.el9 | 15.09.2022 |
SB2022091520 SB2022091521 SB2022092144 and 127 more |
||
| #VU64266 - Buffer overflow CVE-2022-24675 |
CWE-120 | Low | 1.4.2-1.rhaos4.11.el8 | 14.06.2022 |
SB2022041004 SB2022061422 SB2022061511 and 88 more |
Showing elements 41 - 60 out of 76