Known vulnerabilities in libtdb (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:libtdb_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 10
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 7.7

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting libtdb (Red Hat package) libtdb (Red Hat package) is affected by 10 known vulnerabilities: 1 high, 9 medium Critical High Medium Low

Vulnerabilities (10)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU24466 - Improper input validation
CVE-2019-14907
CWE-20 Medium
No
No
1.4.2-4.el7rhgs 21.01.2020 SB2020012110
SB2020012301
SB2020012905
and 10 more
#VU22329 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2019-10218
CWE-22 Medium
No
No
1.4.2-4.el7rhgs 29.10.2019 SB2019102910
SB2019103005
SB2019110304
and 13 more
#VU241 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2118
CWE-300 High
No
No
1.3.8-1.el7_1, 1.3.8-1.el6rhs, 1.3.8-1.el7rhgs 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 25 more
#VU240 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2115
CWE-300 Medium
No
No
1.3.8-1.el7_1, 1.3.8-1.el6rhs, 1.3.8-1.el7rhgs 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 24 more
#VU239 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2114
CWE-300 Medium
No
No
1.3.8-1.el7_1, 1.3.8-1.el6rhs, 1.3.8-1.el7rhgs 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 11 more
#VU238 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2113
CWE-300 Medium
No
No
1.3.8-1.el7_1, 1.3.8-1.el6rhs, 1.3.8-1.el7rhgs 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 16 more
#VU237 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2112
CWE-300 Medium
No
No
1.3.8-1.el7_1, 1.3.8-1.el6rhs, 1.3.8-1.el7rhgs 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 24 more
#VU236 - Authentication Bypass by Spoofing
CVE-2016-2111
CWE-290 Medium
No
No
1.3.8-1.el7_1, 1.3.8-1.el6rhs, 1.3.8-1.el7rhgs 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 25 more
#VU235 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2110
CWE-300 Medium
No
No
1.3.8-1.el7_1, 1.3.8-1.el6rhs, 1.3.8-1.el7rhgs 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 25 more
#VU234 - Resource exhaustion
CVE-2015-5370
CWE-400 Medium
No
No
1.3.8-1.el7_1, 1.3.8-1.el6rhs, 1.3.8-1.el7rhgs 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 22 more