Known vulnerabilities in evolution-mapi (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:evolution-mapi_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 15
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting evolution-mapi (Red Hat package) evolution-mapi (Red Hat package) is affected by 15 known vulnerabilities: 2 high, 11 medium, 2 low Critical High Medium Low

Vulnerabilities (15)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU78577 - Out-of-bounds read
CVE-2022-2127
CWE-125 Medium
No
No
3.28.3-8.el8, 3.40.1-6.el9 24.07.2023 SB2023072430
SB2023072432
SB2023072433
and 34 more
#VU78576 - Exposure of sensitive information to an unauthorized actor
CVE-2023-34968
CWE-200 Low
No
No
3.28.3-8.el8, 3.40.1-6.el9 24.07.2023 SB2023072431
SB2023072432
SB2023072437
and 27 more
#VU78575 - Type confusion
CVE-2023-34967
CWE-843 Medium
No
No
3.28.3-8.el8, 3.40.1-6.el9 24.07.2023 SB2023072431
SB2023072432
SB2023072437
and 32 more
#VU78574 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2023-34966
CWE-835 Medium
No
No
3.28.3-8.el8, 3.40.1-6.el9 24.07.2023 SB2023072431
SB2023072432
SB2023072437
and 35 more
#VU67583 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2007-4559
CWE-22 High
Available
No
3.28.3-8.el8, 3.40.1-6.el9 22.09.2022 SB2007082801
SB2022120206
SB2023060825
and 68 more
#VU67270 - Use of Insufficiently Random Values
CVE-2022-1615
CWE-330 Low
No
No
3.28.3-7.el8, 3.40.1-5.el9 13.09.2022 SB2022091371
SB2022091377
SB2022091448
and 18 more
#VU34139 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2020-14928
CWE-74 Medium
No
No
3.28.3-3.el8 17.07.2020 SB2020071733
SB2020110511
SB2020071815
and 6 more
#VU241 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2118
CWE-300 High
No
No
0.28.3-8.el6_2 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 25 more
#VU240 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2115
CWE-300 Medium
No
No
0.28.3-8.el6_2 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 24 more
#VU239 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2114
CWE-300 Medium
No
No
0.28.3-8.el6_2 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 11 more
#VU238 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2113
CWE-300 Medium
No
No
0.28.3-8.el6_2 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 16 more
#VU237 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2112
CWE-300 Medium
No
No
0.28.3-8.el6_2 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 24 more
#VU236 - Authentication Bypass by Spoofing
CVE-2016-2111
CWE-290 Medium
No
No
0.28.3-8.el6_2 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 25 more
#VU235 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2110
CWE-300 Medium
No
No
0.28.3-8.el6_2 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 25 more
#VU234 - Resource exhaustion
CVE-2015-5370
CWE-400 Medium
No
No
0.28.3-8.el6_2 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 22 more