Known vulnerabilities in LibRaw (Red Hat package)
Vendor:
Red Hat Inc.
Software:
LibRaw (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:libraw_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
65
Public exploits:
3
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
0.19.5-2.el8_4.2
0.19.5-3.el8_6.2
0.19.5-3.el8_8.2
0.19.5-3.el8_8.1
0.19.5-3.el8_6.1
0.19.5-2.el8_4.1
0.21.1-2.el9_4
0.20.2-6.el9_2
0.20.2-6.el9_0
0.21.1-2.el9_6
0.19.5-6.el8_10
0.21.1-2.el9_7
0.19.5-4.el8
0.21.1-1.el9
0.19.4-2.el7_9
0.20.2-6.el9
0.19.5-3.el8
0.19.5-2.el8
0.19.5-1.el8
0.19.2-1.el7
0.19.4-1.el7
Vulnerabilities (65)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU125292 - Heap-based Buffer Overflow CVE-2026-20889 |
CWE-122 | High | 0.19.5-2.el8_4.1, 0.19.5-3.el8_6.1, 0.19.5-3.el8_8.1, 0.19.5-6.el8_10 | 08.04.2026 |
SB2026040857 SB20260408160 SB20260408161 and 7 more |
||
| #VU125230 - Heap-based Buffer Overflow CVE-2026-21413 |
CWE-122 | High | 0.19.5-2.el8_4.1, 0.19.5-3.el8_6.1, 0.19.5-3.el8_8.1, 0.19.5-6.el8_10, 0.20.2-6.el9_0, 0.20.2-6.el9_2, 0.21.1-2.el9_4, 0.21.1-2.el9_6, 0.21.1-2.el9_7 | 08.04.2026 |
SB2026040857 SB20260408160 SB20260408161 and 13 more |
||
| #VU125197 - Heap-based Buffer Overflow CVE-2026-24660 |
CWE-122 | High | 0.19.5-2.el8_4.2, 0.19.5-3.el8_6.2, 0.19.5-3.el8_8.2, 0.19.5-6.el8_10 | 08.04.2026 |
SB2026040857 SB20260408160 SB20260408161 and 7 more |
||
| #VU125195 - Integer overflow CVE-2026-24450 |
CWE-190 | High | 0.21.1-2.el9_4, 0.21.1-2.el9_6, 0.21.1-2.el9_7 | 08.04.2026 |
SB2026040857 SB20260408160 SB20260408161 and 6 more |
||
| #VU76158 - Heap-based Buffer Overflow CVE-2023-1729 |
CWE-122 | High | 0.21.1-1.el9 | 15.05.2023 |
SB2023051536 SB2023051537 SB2023051538 and 15 more |
||
| #VU72570 - Memory corruption CVE-2021-32142 |
CWE-119 | High | 0.19.4-2.el7_9, 0.19.5-4.el8, 0.20.2-6.el9 | 25.02.2023 |
SB2023022501 SB2023022508 SB2023022509 and 19 more |
||
| #VU31920 - Memory corruption CVE-2020-15503 |
CWE-119 | Medium | 0.19.5-2.el8 | 27.07.2020 |
SB2020070228 SB2020072741 SB2020080204 and 12 more |
||
| #VU26432 - Business Logic Errors (3.0) CVE-2020-3885 |
CWE-840 | Low | 0.19.5-2.el8 | 27.03.2020 |
SB2020032715 SB2020032719 SB2020051104 and 8 more |
||
| #VU26431 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2020-3902 |
CWE-79 | Low | 0.19.5-2.el8 | 27.03.2020 |
SB2020032715 SB2020032719 SB2020051104 and 10 more |
||
| #VU26430 - Memory corruption CVE-2020-3899 |
CWE-119 | High | 0.19.5-2.el8 | 27.03.2020 |
SB2020032715 SB2020032719 SB2020042823 and 12 more |
||
| #VU26428 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2020-3894 |
CWE-362 | Medium | 0.19.5-2.el8 | 27.03.2020 |
SB2020032715 SB2020032719 SB2020051104 and 8 more |
||
| #VU26427 - Memory corruption CVE-2020-3900 |
CWE-119 | High | 0.19.5-2.el8 | 27.03.2020 |
SB2020032715 SB2020032718 SB2020032719 and 9 more |
||
| #VU26426 - Memory corruption CVE-2020-3895 |
CWE-119 | High | 0.19.5-2.el8 | 27.03.2020 |
SB2020032715 SB2020032718 SB2020032719 and 9 more |
||
| #VU26424 - Type confusion CVE-2020-3901 |
CWE-843 | High | 0.19.5-2.el8 | 27.03.2020 |
SB2020032715 SB2020032718 SB2020032719 and 9 more |
||
| #VU26422 - Type confusion CVE-2020-3897 |
CWE-843 | High | 0.19.5-2.el8 | 27.03.2020 |
SB2020032715 SB2020032718 SB2020032719 and 9 more |
||
| #VU25382 - Memory corruption CVE-2020-3868 |
CWE-119 | High | 0.19.5-2.el8 | 15.02.2020 |
SB2020021501 SB2020021717 SB2020021808 and 8 more |
||
| #VU25381 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2020-3867 |
CWE-79 | Medium | 0.19.5-2.el8 | 15.02.2020 |
SB2020021501 SB2020021717 SB2020021808 and 8 more |
||
| #VU25380 - Origin Validation Error CVE-2020-3865 |
CWE-346 | Medium | 0.19.5-2.el8 | 15.02.2020 |
SB2020021501 SB2020021717 SB2020021808 and 8 more |
||
| #VU25379 - Origin Validation Error CVE-2020-3864 |
CWE-346 | Medium | 0.19.5-2.el8 | 15.02.2020 |
SB2020021501 SB2020021717 SB2020021808 and 8 more |
||
| #VU25375 - Memory corruption CVE-2020-3862 |
CWE-119 | Low | 0.19.5-2.el8 | 14.02.2020 |
SB2020021501 SB2020021717 SB2020021808 and 8 more |
Showing elements 1 - 20 out of 65