Known vulnerabilities in gnutls (Red Hat package) - page 2

Software CPE: cpe:2.3:o:red_hat:gnutls_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 39
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting gnutls (Red Hat package) gnutls (Red Hat package) is affected by 39 known vulnerabilities: 4 high, 26 medium, 9 low Critical High Medium Low

Vulnerabilities (39)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU112994 - NULL Pointer Dereference
CVE-2025-32990
CWE-476 Low
No
No
3.6.16-8.el8_10.4, 3.7.6-21.el9_2.4, 3.8.3-4.el9_4.4, 3.8.3-6.el9_6.2, 3.8.9-9.el10_0.14 16.07.2025 SB20250716122
SB20250716123
SB20250716124
and 79 more
#VU87672 - Improper input validation
CVE-2024-28835
CWE-20 Medium
No
No
3.7.6-21.el9_2.3, 3.7.6-23.el9_3.4, 3.8.3-4.el9_4 20.03.2024 SB2024032057
SB2024032058
SB2024032059
and 71 more
#VU87671 - Cryptographic Issues
CVE-2024-28834
CWE-310 Medium
No
No
3.6.16-5.el8_6.4, 3.6.16-7.el8_8.3, 3.6.16-8.el8_9.3, 3.7.6-21.el9_2.3, 3.7.6-23.el9_3.4, 3.8.3-4.el9_4 20.03.2024 SB2024032057
SB2024032058
SB2024032059
and 111 more
#VU85624 - Reachable Assertion
CVE-2024-0567
CWE-617 Medium
No
No
3.7.6-21.el9_2.2, 3.7.6-23.el9_3.3 21.01.2024 SB2024012105
SB2024012106
SB2024012234
and 34 more
#VU85623 - Information Exposure Through Timing Discrepancy
CVE-2024-0553
CWE-208 Medium
No
No
3.6.16-5.el8_6.3, 3.6.16-7.el8_8.2, 3.6.16-8.el8_9.1, 3.7.6-21.el9_2.2, 3.7.6-23.el9_3.3 21.01.2024 SB2024012105
SB2024012106
SB2024012234
and 78 more
#VU83316 - Information Exposure Through Timing Discrepancy
CVE-2023-5981
CWE-208 Medium
No
No
3.6.16-5.el8_6.2, 3.6.16-5.el8_6.3, 3.6.16-7.el8_8.1, 3.6.16-7.el8_8.2, 3.6.16-8.el8_9, 3.6.16-8.el8_9.1, 3.7.6-21.el9_2.2, 3.7.6-23.el9_3.3 20.11.2023 SB2023112075
SB2023112145
SB2023120164
and 79 more
#VU72125 - Inadequate Encryption Strength
CVE-2023-0361
CWE-326 Medium
No
No
3.6.16-5.el8_6.1, 3.6.16-6.el8_7, 3.7.6-18.el9_0, 3.7.6-18.el9_1 11.02.2023 SB2023021103
SB2023021109
SB2023021561
and 88 more
#VU65915 - Double Free
CVE-2022-2509
CWE-415 High
No
No
3.6.16-5.el8_6, 3.7.6-12.el9_0 02.08.2022 SB2022080207
SB2022080208
SB2022080509
and 54 more
#VU53978 - Improper input validation
CVE-2021-3580
CWE-20 Medium
No
No
3.6.16-4.el8 09.06.2021 SB2021060918
SB2021060919
SB2021061812
and 22 more
#VU52195 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2021-20305
CWE-327 High
No
No
3.6.8-10.el8_1, 3.6.8-12.el8_2, 3.6.14-8.el8_3 06.04.2021 SB2021041367
SB2021041616
SB2021041803
and 36 more
#VU51442 - Use After Free
CVE-2021-20232
CWE-416 Low
No
No
3.6.16-4.el8 14.03.2021 SB2021031401
SB2021031402
SB2021092209
and 21 more
#VU51441 - Use After Free
CVE-2021-20231
CWE-416 Low
No
No
3.6.16-4.el8 14.03.2021 SB2021031401
SB2021031402
SB2021092209
and 21 more
#VU46295 - NULL Pointer Dereference
CVE-2020-24659
CWE-476 Medium
No
No
3.6.14-7.el8_3 04.09.2020 SB2020090415
SB2020090416
SB2020090604
and 11 more
#VU28557 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2020-13777
CWE-300 Medium
Available
No
3.6.8-9.el8_1, 3.6.8-11.el8_2 04.06.2020 SB2020060401
SB2020060402
SB2020060606
and 13 more
#VU26487 - Use of Insufficiently Random Values
CVE-2020-11501
CWE-330 Medium
No
No
3.6.8-10.el8_2 31.03.2020 SB2020033128
SB2020033129
SB2020040316
and 7 more
#VU7660 - Heap-based Buffer Overflow
CVE-2017-5337
CWE-122 Low
No
No
2.12.23-21.el6 02.08.2017 SB2017011009
SB2017080109
SB2017021003
and 11 more
#VU7658 - Stack-based buffer overflow
CVE-2017-5336
CWE-121 Low
No
No
2.12.23-21.el6 02.08.2017 SB2017011009
SB2017080109
SB2017021003
and 11 more
#VU7657 - Memory corruption
CVE-2017-5335
CWE-119 Low
No
No
2.12.23-21.el6 02.08.2017 SB2017011009
SB2017080109
SB2017021003
and 10 more
#VU1083 - Error Handling
CVE-2016-8610
CWE-388 Low
No
No
2.12.23-21.el6 24.10.2016 SB2017060704
SB2017032005
SB2017020101
and 17 more


Showing elements 21 - 40 out of 39