Known vulnerabilities in evince (Red Hat package)
Vendor:
Red Hat Inc.
Software:
evince (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:evince_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
14
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
3.28.4-16.el8_6.1
3.28.4-11.el8_4.1
3.28.4-16.el8_8.1
40.5-2.el9_2.1
40.5-2.el9_4.1
40.5-2.el9_6.1
3.28.4-17.el8_10
40.5-4.el9_8.1
2.28.2-14.el6_0.1
3.28.4-11.el8
3.28.2-9.el7
3.28.2-10.el7
3.28.4-4.el8
3.28.4-3.el8
3.28.2-8.el7
3.22.1-5.2.el7_4
2.28.2-20.el6
2.28.2-19.el6
2.28.2-14.el6_0
2.28.2-14.el6
Vulnerabilities (14)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU132128 - Argument Injection or Modification CVE-2026-46529 |
CWE-88 | High | 3.28.4-11.el8_4.1, 3.28.4-16.el8_6.1, 3.28.4-16.el8_8.1, 3.28.4-17.el8_10, 40.5-2.el9_2.1, 40.5-2.el9_4.1, 40.5-2.el9_6.1, 40.5-4.el9_8.1 | 22.05.2026 |
SB2026052222 SB2026052223 SB2026052224 and 18 more |
||
| #VU82603 - Access of Uninitialized Pointer CVE-2020-27778 |
CWE-824 | Low | 3.28.4-11.el8 | 31.10.2023 |
SB2019090505 SB2021101517 SB2021051956 and 2 more |
||
| #VU29244 - Access of Uninitialized Pointer CVE-2019-11459 |
CWE-824 | Low | 3.28.2-9.el7, 3.28.4-3.el8 | 25.06.2020 |
SB2019042313 SB2020071719 SB2019100321 and 8 more |
||
| #VU20888 - Integer overflow CVE-2018-21009 |
CWE-190 | High | 3.28.2-9.el7 | 05.09.2019 |
SB2019090505 SB2020071719 SB2020040196 and 4 more |
||
| #VU20053 - Divide By Zero CVE-2019-14494 |
CWE-369 | Low | 3.28.2-10.el7 | 12.08.2019 |
SB2019080101 SB2019081204 SB2020093030 and 5 more |
||
| #VU19598 - Out-of-bounds read CVE-2019-10871 |
CWE-125 | Low | 3.28.2-9.el7 | 01.08.2019 |
SB2019040512 SB2019091040 SB2020071719 and 6 more |
||
| #VU19596 - Out-of-bounds read CVE-2019-12293 |
CWE-125 | Low | 3.28.2-9.el7 | 01.08.2019 |
SB2019052309 SB2019091040 SB2020071719 and 6 more |
||
| #VU19570 - Integer overflow CVE-2019-9959 |
CWE-190 | Medium | 3.28.2-9.el7 | 31.07.2019 |
SB2019080101 SB2019091040 SB2020071719 and 6 more |
||
| #VU18791 - Permissions, Privileges, and Access Controls CVE-2019-12795 |
CWE-264 | Low | 3.28.4-3.el8 | 13.06.2019 |
SB2019070801 SB2019070802 SB2019072234 and 5 more |
||
| #VU18678 - Permissions, Privileges, and Access Controls CVE-2019-12447 |
CWE-264 | Critical | 3.28.4-4.el8 | 05.06.2019 |
SB2019070801 SB2019070802 SB2020042843 and 3 more |
||
| #VU18677 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2019-12448 |
CWE-362 | High | 3.28.4-4.el8 | 05.06.2019 |
SB2019070801 SB2019070802 SB2020042843 and 3 more |
||
| #VU18676 - Permissions, Privileges, and Access Controls CVE-2019-12449 |
CWE-264 | Critical | 3.28.4-4.el8 | 05.06.2019 |
SB2019070801 SB2019070802 SB2020042843 and 3 more |
||
| #VU17666 - Permissions, Privileges, and Access Controls CVE-2019-3825 |
CWE-264 | Low | 3.28.4-4.el8 | 14.02.2019 |
SB2019021402 SB2019030810 SB2019030304 and 4 more |
||
| #VU16692 - Stack-based buffer overflow CVE-2018-20337 |
CWE-121 | Low | 3.28.4-4.el8 | 25.12.2018 |
SB2018122504 SB2019012912 SB2019052213 and 2 more |