Known vulnerabilities in jbcs-httpd24-mod_md (Red Hat package) - page 4
Vendor:
Red Hat Inc.
Software:
jbcs-httpd24-mod_md (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:jbcs-httpd24-mod_md_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
128
Public exploits:
14
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2.4.28-16.el7jbcs
2.4.28-16.el8jbcs
2.4.28-13.el7jbcs
2.4.28-13.el8jbcs
2.4.28-10.el7jbcs
2.4.28-10.el8jbcs
2.4.24-13.el7jbcs
2.4.24-13.el8jbcs
2.4.24-11.el7jbcs
2.4.24-11.el8jbcs
2.4.24-6.el7jbcs
2.4.24-6.el8jbcs
2.4.24-4.el7jbcs
2.4.24-4.el8jbcs
2.4.24-2.el7jbcs
2.4.24-2.el8jbcs
2.4.0-27.el7jbcs
2.4.0-27.el8jbcs
2.4.0-25.el7jbcs
2.4.0-25.el8jbcs
2.4.0-20.el7jbcs
2.4.0-20.el8jbcs
2.0.8-30.jbcs.el6
2.0.8-30.jbcs.el7
2.4.0-18.el7jbcs
2.4.0-18.el8jbcs
2.4.0-15.el7jbcs
2.4.0-15.el8jbcs
2.0.8-41.jbcs.el7
2.0.8-41.el8jbcs
2.0.8-40.jbcs.el7
2.0.8-40.el8jbcs
2.0.8-38.jbcs.el7
2.0.8-38.el8jbcs
2.0.8-36.jbcs.el7
2.0.8-36.el8jbcs
2.0.8-33.jbcs.el7
2.0.8-31.jbcs.el7
2.0.8-24.jbcs.el6
2.0.8-24.jbcs.el7
Vulnerabilities (128)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU64559 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2022-2068 |
CWE-78 | Medium | 2.4.0-18.el7jbcs, 2.4.0-18.el8jbcs | 21.06.2022 |
SB2022062120 SB2022062125 SB2022062236 and 135 more |
||
| #VU64083 - Out-of-bounds read CVE-2022-28615 |
CWE-125 | Low | 2.4.0-18.el7jbcs, 2.4.0-18.el8jbcs | 08.06.2022 |
SB2022060817 SB2022060901 SB2022061611 and 41 more |
||
| #VU64081 - Out-of-bounds read CVE-2022-28614 |
CWE-125 | Low | 2.4.0-18.el7jbcs, 2.4.0-18.el8jbcs | 08.06.2022 |
SB2022060817 SB2022060901 SB2022061611 and 36 more |
||
| #VU64080 - Out-of-bounds read CVE-2022-28330 |
CWE-125 | Medium | 2.4.0-18.el7jbcs, 2.4.0-18.el8jbcs | 08.06.2022 |
SB2022060817 SB2022060901 SB2022070730 and 11 more |
||
| #VU64078 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-26377 |
CWE-444 | Medium | 2.4.0-18.el7jbcs, 2.4.0-18.el8jbcs | 08.06.2022 |
SB2022060817 SB2022060901 SB2022061611 and 39 more |
||
| #VU62765 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2022-1292 |
CWE-78 | Medium | 2.4.0-18.el7jbcs, 2.4.0-18.el8jbcs | 03.05.2022 |
SB2022050315 SB2022050436 SB2022050503 and 141 more |
||
| #VU61285 - Integer overflow CVE-2022-22721 |
CWE-190 | High | 2.4.0-18.el7jbcs, 2.4.0-18.el8jbcs | 14.03.2022 |
SB2022031416 SB2022031504 SB2022031724 and 39 more |
||
| #VU61284 - Out-of-bounds write CVE-2022-23943 |
CWE-787 | High | 2.4.0-18.el7jbcs, 2.4.0-18.el8jbcs | 14.03.2022 |
SB2022031416 SB2022031504 SB2022031724 and 34 more |
||
| #VU60739 - Integer overflow CVE-2022-25315 |
CWE-190 | High | 2.4.0-15.el7jbcs, 2.4.0-15.el8jbcs | 21.02.2022 |
SB2022022109 SB2022022113 SB2022022411 and 99 more |
||
| #VU60738 - Integer overflow CVE-2022-25314 |
CWE-190 | Medium | 2.4.0-15.el7jbcs, 2.4.0-15.el8jbcs | 21.02.2022 |
SB2022022109 SB2022022113 SB2022022411 and 68 more |
||
| #VU60737 - Stack-based buffer overflow CVE-2022-25313 |
CWE-121 | High | 2.4.0-15.el7jbcs, 2.4.0-15.el8jbcs | 21.02.2022 |
SB2022022109 SB2022022113 SB2022022411 and 64 more |
||
| #VU60736 - Improper Control of Generation of Code ('Code Injection') CVE-2022-25235 |
CWE-94 | High | 2.4.0-15.el7jbcs, 2.4.0-15.el8jbcs | 21.02.2022 |
SB2022022109 SB2022022113 SB2022022411 and 106 more |
||
| #VU60733 - Improper input validation CVE-2022-25236 |
CWE-20 | Medium | 2.4.0-15.el7jbcs, 2.4.0-15.el8jbcs | 21.02.2022 |
SB2022022109 SB2022022113 SB2022022411 and 109 more |
||
| #VU60114 - Integer overflow CVE-2022-23990 |
CWE-190 | High | 2.4.0-15.el7jbcs, 2.4.0-15.el8jbcs | 28.01.2022 |
SB2022012504 SB2022012804 SB2022020902 and 46 more |
||
| #VU59966 - Integer overflow CVE-2022-23852 |
CWE-190 | High | 2.4.0-15.el7jbcs, 2.4.0-15.el8jbcs | 25.01.2022 |
SB2022012504 SB2022012622 SB2022020902 and 58 more |
||
| #VU59650 - Integer overflow CVE-2022-22827 |
CWE-190 | High | 2.4.0-15.el7jbcs, 2.4.0-15.el8jbcs | 17.01.2022 |
SB2022011711 SB2022011713 SB2022020902 and 54 more |
||
| #VU59649 - Integer overflow CVE-2022-22826 |
CWE-190 | High | 2.4.0-15.el7jbcs, 2.4.0-15.el8jbcs | 17.01.2022 |
SB2022011711 SB2022011713 SB2022020902 and 54 more |
||
| #VU59648 - Integer overflow CVE-2022-22825 |
CWE-190 | High | 2.4.0-15.el7jbcs, 2.4.0-15.el8jbcs | 17.01.2022 |
SB2022011711 SB2022011713 SB2022020902 and 56 more |
||
| #VU59647 - Integer overflow CVE-2022-22824 |
CWE-190 | High | 2.4.0-15.el7jbcs, 2.4.0-15.el8jbcs | 17.01.2022 |
SB2022011711 SB2022011713 SB2022020902 and 57 more |
||
| #VU56474 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2021-33193 |
CWE-444 | Medium | 2.4.0-15.el7jbcs, 2.4.0-15.el8jbcs | 13.09.2021 |
SB2021091317 SB2021091707 SB2021092301 and 24 more |
Showing elements 61 - 80 out of 128