Known vulnerabilities in gnome-boxes (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:gnome-boxes_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 12
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting gnome-boxes (Red Hat package) gnome-boxes (Red Hat package) is affected by 12 known vulnerabilities: 2 critical, 6 high, 4 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU48720 - Use After Free
CVE-2020-13543
CWE-416 High
No
No
3.36.5-8.el8 01.12.2020 SB2020112408
SB2020122344
SB2021040169
and 7 more
#VU48617 - Use After Free
CVE-2020-13584
CWE-416 High
No
No
3.36.5-8.el8 24.11.2020 SB2020112408
SB2020112602
SB2020112618
and 11 more
#VU46804 - Out-of-bounds write
CVE-2020-9983
CWE-787 High
No
No
3.36.5-8.el8 18.09.2020 SB2020091802
SB2020112408
SB2020112602
and 13 more
#VU46802 - Use After Free
CVE-2020-9951
CWE-416 High
No
No
3.36.5-8.el8 18.09.2020 SB2020091802
SB2020112408
SB2020112602
and 14 more
#VU46801 - Type confusion
CVE-2020-9948
CWE-843 High
No
No
3.36.5-8.el8 18.09.2020 SB2020091802
SB2020112408
SB2020112602
and 14 more
#VU18944 - Incorrect Default Permissions
CVE-2019-13012
CWE-276 Low
No
No
3.36.5-8.el8 29.06.2019 SB2019062905
SB2019072003
SB2019091144
and 9 more
#VU18678 - Permissions, Privileges, and Access Controls
CVE-2019-12447
CWE-264 Critical
No
No
3.28.5-8.el8 05.06.2019 SB2019070801
SB2019070802
SB2020042843
and 3 more
#VU18677 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2019-12448
CWE-362 High
No
No
3.28.5-8.el8 05.06.2019 SB2019070801
SB2019070802
SB2020042843
and 3 more
#VU18676 - Permissions, Privileges, and Access Controls
CVE-2019-12449
CWE-264 Critical
No
No
3.28.5-8.el8 05.06.2019 SB2019070801
SB2019070802
SB2020042843
and 3 more
#VU17666 - Permissions, Privileges, and Access Controls
CVE-2019-3825
CWE-264 Low
No
No
3.28.5-8.el8 14.02.2019 SB2019021402
SB2019030810
SB2019030304
and 4 more
#VU17353 - Improper input validation
CVE-2018-5819
CWE-20 Low
No
No
3.28.5-4.el7 01.02.2019 SB2019012912
SB2019052213
SB2019080638
and 1 more
#VU16692 - Stack-based buffer overflow
CVE-2018-20337
CWE-121 Low
No
No
3.28.5-8.el8 25.12.2018 SB2018122504
SB2019012912
SB2019052213
and 2 more