Known vulnerabilities in fwupd (Red Hat package)
Vendor:
Red Hat Inc.
Software:
fwupd (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:fwupd_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
19
Public exploits:
4
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
Vulnerabilities (19)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU75912 - Weak Password Requirements CVE-2022-3287 |
CWE-521 | Low | 1.7.8-2.el8, 1.7.8-2.el8_8, 1.8.10-2.el9 | 09.05.2023 |
SB20230509102 SB20230509107 SB2023042426 and 5 more |
||
| #VU66350 - Security Features CVE-2022-34303 |
CWE-254 | Low | 1.8.10-2.el9 | 10.08.2022 |
SB2022081014 SB20230509107 SB2023042426 |
||
| #VU66349 - Security Features CVE-2022-34301 |
CWE-254 | Low | 1.8.10-2.el9 | 10.08.2022 |
SB2022081013 SB20230509107 SB2023042426 |
||
| #VU66348 - Security Features CVE-2022-34302 |
CWE-254 | Low | 1.8.10-2.el9 | 10.08.2022 |
SB2022081012 SB20230509107 SB2023042426 |
||
| #VU51198 - Out-of-bounds write CVE-2021-20233 |
CWE-787 | Low | 1.1.4-4.el8_1, 1.1.4-9.el8_2, 1.5.9-1.el8_4 | 03.03.2021 |
SB2021030311 SB2021030401 SB2021030402 and 37 more |
||
| #VU51197 - Out-of-bounds write CVE-2021-20225 |
CWE-787 | Low | 1.1.4-4.el8_1, 1.1.4-9.el8_2, 1.5.9-1.el8_4 | 03.03.2021 |
SB2021030311 SB2021030401 SB2021030402 and 37 more |
||
| #VU51194 - Improper Authorization CVE-2020-27779 |
CWE-285 | Low | 1.1.4-4.el8_1, 1.1.4-9.el8_2, 1.5.9-1.el8_4 | 03.03.2021 |
SB2021030311 SB2021030401 SB2021030402 and 37 more |
||
| #VU51193 - Stack-based buffer overflow CVE-2020-27749 |
CWE-121 | Low | 1.1.4-4.el8_1, 1.1.4-9.el8_2, 1.5.9-1.el8_4 | 03.03.2021 |
SB2021030311 SB2021030401 SB2021030402 and 37 more |
||
| #VU51189 - Out-of-bounds write CVE-2020-25647 |
CWE-787 | Low | 1.1.4-4.el8_1, 1.1.4-9.el8_2, 1.5.9-1.el8_4 | 03.03.2021 |
SB2021030311 SB2021030401 SB2021030402 and 35 more |
||
| #VU51188 - Use After Free CVE-2020-25632 |
CWE-416 | Low | 1.1.4-4.el8_1, 1.1.4-9.el8_2, 1.5.9-1.el8_4 | 03.03.2021 |
SB2021030311 SB2021030401 SB2021030402 and 37 more |
||
| #VU51187 - Permissions, Privileges, and Access Controls CVE-2020-14372 |
CWE-264 | Low | 1.1.4-4.el8_1, 1.1.4-9.el8_2, 1.5.9-1.el8_4 | 03.03.2021 |
SB2021030311 SB2021030401 SB2021030402 and 37 more |
||
| #VU32936 - Integer overflow CVE-2020-14311 |
CWE-190 | Low | 1.1.4-2.el8_1, 1.1.4-7.el8_2 | 30.07.2020 |
SB2020073018 SB2020073035 SB2020073036 and 17 more |
||
| #VU32935 - Integer overflow CVE-2020-14310 |
CWE-190 | Low | 1.1.4-2.el8_1, 1.1.4-7.el8_2 | 30.07.2020 |
SB2020073018 SB2020073035 SB2020073036 and 17 more |
||
| #VU32934 - Integer overflow CVE-2020-14309 |
CWE-190 | Low | 1.1.4-2.el8_1, 1.1.4-7.el8_2 | 30.07.2020 |
SB2020073018 SB2020073035 SB2020073036 and 17 more |
||
| #VU32927 - Improper Verification of Cryptographic Signature CVE-2020-15705 |
CWE-347 | Low | 1.1.4-2.el8_1, 1.1.4-7.el8_2 | 30.07.2020 |
SB2020073017 SB2020073035 SB2020073036 and 16 more |
||
| #VU32926 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2020-15706 |
CWE-362 | Low | 1.1.4-2.el8_1, 1.1.4-7.el8_2 | 30.07.2020 |
SB2020073017 SB2020073035 SB2020073036 and 17 more |
||
| #VU32925 - Integer overflow CVE-2020-15707 |
CWE-190 | Low | 1.1.4-2.el8_1, 1.1.4-7.el8_2 | 30.07.2020 |
SB2020073017 SB2020073035 SB2020073036 and 16 more |
||
| #VU32923 - Heap-based Buffer Overflow CVE-2020-14308 |
CWE-122 | Low | 1.1.4-2.el8_1, 1.1.4-7.el8_2 | 30.07.2020 |
SB2020073018 SB2020073035 SB2020073036 and 17 more |
||
| #VU32922 - Out-of-bounds write CVE-2020-10713 |
CWE-787 | Low | 1.1.4-2.el8_1, 1.1.4-7.el8_2 | 30.07.2020 |
SB2020073018 SB2020073026 SB2020073027 and 33 more |