Known vulnerabilities in cyrus-sasl (Red Hat package)
Vendor:
Red Hat Inc.
Software:
cyrus-sasl (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:cyrus-sasl_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
2
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU60842 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2022-24407 |
CWE-89 | High | 2.1.23-16.el6_10, 2.1.26-24.el7_9, 2.1.27-2.el8_1, 2.1.27-2.el8_2, 2.1.27-6.el8_4, 2.1.27-6.el8_5 | 24.02.2022 |
SB2022022409 SB2022022410 SB2022022421 and 67 more |
||
| #VU23796 - Out-of-bounds write CVE-2019-19906 |
CWE-787 | Medium | 2.1.27-5.el8 | 23.12.2019 |
SB2019122303 SB2019122304 SB2020012820 and 15 more |