Known vulnerabilities in libtalloc (Red Hat package)
Vendor:
Red Hat Inc.
Software:
libtalloc (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:libtalloc_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
11
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
7.7
Breakdown by Severity Chart
2.4.3-1.el9
2.4.1-1.el9
2.4.2-1.el9
2.3.3-2.el8rhgs
2.3.2-5.el8rhgs
2.2.0-9.el7rhgs
2.1.14-3.el6rhs
2.1.14-3.el7rhgs
2.1.11-1.el7rhgs
2.1.11-1.el6rhs
2.1.9-1.el6rhs
2.1.1-4.el6rhs
2.1.5-1.el6rhs
2.1.5-1.el7rhgs
2.1.5-1.el7_1
2.1.14-3.el7
2.1.13-1.el7
2.1.11-1.el7
2.1.10-4.el7
2.1.10-1.el7
2.1.9-1.el7
2.1.6-1.el7
2.1.5-1.el7
2.1.2-1.el7
2.1.1-4.el7
2.1.5-1.el6_7
2.0.7-2.el6
2.1.14-3.el6
2.1.11-1.el6
2.1.10-4.el6
2.1.9-1.el6
2.1.6-1.el6
2.1.5-1.el6
2.1.2-1.el6
2.1.1-4.el6
2.1.1-3.el6
Vulnerabilities (11)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU52748 - Out-of-bounds read CVE-2021-20254 |
CWE-125 | Medium | 2.3.2-5.el8rhgs | 29.04.2021 |
SB2021042916 SB2021052619 SB2021060941 and 30 more |
||
| #VU24466 - Improper input validation CVE-2019-14907 |
CWE-20 | Medium | 2.2.0-9.el7rhgs | 21.01.2020 |
SB2020012110 SB2020012301 SB2020012905 and 10 more |
||
| #VU22329 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2019-10218 |
CWE-22 | Medium | 2.2.0-9.el7rhgs | 29.10.2019 |
SB2019102910 SB2019103005 SB2019110304 and 13 more |
||
| #VU241 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2016-2118 |
CWE-300 | High | 2.1.5-1.el7_1, 2.1.5-1.el6rhs, 2.1.5-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 25 more |
||
| #VU240 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2016-2115 |
CWE-300 | Medium | 2.1.5-1.el7_1, 2.1.5-1.el6rhs, 2.1.5-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 24 more |
||
| #VU239 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2016-2114 |
CWE-300 | Medium | 2.1.5-1.el7_1, 2.1.5-1.el6rhs, 2.1.5-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 11 more |
||
| #VU238 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2016-2113 |
CWE-300 | Medium | 2.1.5-1.el7_1, 2.1.5-1.el6rhs, 2.1.5-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 16 more |
||
| #VU237 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2016-2112 |
CWE-300 | Medium | 2.1.5-1.el7_1, 2.1.5-1.el6rhs, 2.1.5-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 24 more |
||
| #VU236 - Authentication Bypass by Spoofing CVE-2016-2111 |
CWE-290 | Medium | 2.1.5-1.el7_1, 2.1.5-1.el6rhs, 2.1.5-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 25 more |
||
| #VU235 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2016-2110 |
CWE-300 | Medium | 2.1.5-1.el7_1, 2.1.5-1.el6rhs, 2.1.5-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 25 more |
||
| #VU234 - Resource exhaustion CVE-2015-5370 |
CWE-400 | Medium | 2.1.5-1.el7_1, 2.1.5-1.el6rhs, 2.1.5-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 22 more |