Known vulnerabilities in libtdb (Red Hat package)
Vendor:
Red Hat Inc.
Software:
libtdb (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:libtdb_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
10
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
7.7
Breakdown by Severity Chart
1.4.14-1.el9
1.4.13-1.el9
1.4.9-1.el9
1.4.12-1.el9
1.4.4-2.el8rhgs
1.4.2-4.el7rhgs
1.3.16-3.el6rhs
1.3.16-3.el7rhgs
1.3.15-4.el7rhgs
1.3.15-4.el6rhs
1.3.12-1.1.el6rhs
1.3.8-1.el6rhs
1.3.8-1.el7rhgs
1.3.8-1.el7_1
1.3.16-3.el7
1.3.15-4.el7
1.3.15-3.el7
1.3.15-1.el7
1.3.12-2.el7
1.3.8-1.el7
1.3.6-2.el7
1.3.4-1.el7
1.3.8-3.el6_8
1.3.8-1.el6_7
1.2.10-1.el6
1.2.1-3.el6
1.2.1-2.el6
1.3.16-3.el6
1.3.15-4.el6
1.3.15-3.el6
1.3.8-1.el6
1.3.6-2.el6
1.3.4-1.el6
Vulnerabilities (10)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU24466 - Improper input validation CVE-2019-14907 |
CWE-20 | Medium | 1.4.2-4.el7rhgs | 21.01.2020 |
SB2020012110 SB2020012301 SB2020012905 and 10 more |
||
| #VU22329 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2019-10218 |
CWE-22 | Medium | 1.4.2-4.el7rhgs | 29.10.2019 |
SB2019102910 SB2019103005 SB2019110304 and 13 more |
||
| #VU241 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2016-2118 |
CWE-300 | High | 1.3.8-1.el7_1, 1.3.8-1.el6rhs, 1.3.8-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 25 more |
||
| #VU240 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2016-2115 |
CWE-300 | Medium | 1.3.8-1.el7_1, 1.3.8-1.el6rhs, 1.3.8-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 24 more |
||
| #VU239 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2016-2114 |
CWE-300 | Medium | 1.3.8-1.el7_1, 1.3.8-1.el6rhs, 1.3.8-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 11 more |
||
| #VU238 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2016-2113 |
CWE-300 | Medium | 1.3.8-1.el7_1, 1.3.8-1.el6rhs, 1.3.8-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 16 more |
||
| #VU237 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2016-2112 |
CWE-300 | Medium | 1.3.8-1.el7_1, 1.3.8-1.el6rhs, 1.3.8-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 24 more |
||
| #VU236 - Authentication Bypass by Spoofing CVE-2016-2111 |
CWE-290 | Medium | 1.3.8-1.el7_1, 1.3.8-1.el6rhs, 1.3.8-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 25 more |
||
| #VU235 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2016-2110 |
CWE-300 | Medium | 1.3.8-1.el7_1, 1.3.8-1.el6rhs, 1.3.8-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 25 more |
||
| #VU234 - Resource exhaustion CVE-2015-5370 |
CWE-400 | Medium | 1.3.8-1.el7_1, 1.3.8-1.el6rhs, 1.3.8-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 22 more |