Known vulnerabilities in libtevent (Red Hat package)
Vendor:
Red Hat Inc.
Software:
libtevent (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:libtevent_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
10
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
7.7
Breakdown by Severity Chart
0.17.1-1.el9
0.16.2-1.el9
0.16.0-1.el9
0.16.1-1.el9
0.11.0-1.el8rhgs
0.10.0-4.el7rhgs
0.9.37-3.el6rhs
0.9.37-3.el7rhgs
0.9.35-1.el7rhgs
0.9.35-1.el6rhs
0.9.31-1.el6rhs
0.9.26-1.el6rhs
0.9.26-1.el7rhgs
0.9.26-1.el7_1
0.9.37-3.el7
0.9.36-2.el7
0.9.36-1.el7
0.9.35-1.el7
0.9.34-2.el7
0.9.33-2.el7
0.9.31-2.el7_4
0.9.31-1.el7
0.9.28-1.el7
0.9.26-1.el7
0.9.25-1.el7
0.9.23-1.el7
0.9.26-2.el6_7
0.9.18-3.el6
0.9.18-1.el6_4
0.9.17-1.el6
0.9.8-8.el6
0.9.37-3.el6
0.9.36-2.el6
0.9.35-1.el6
0.9.34-2.el6
0.9.31-1.el6
0.9.28-1.el6
0.9.26-1.el6
0.9.25-1.el6
0.9.23-1.el6
0.9.18-2.el6
Vulnerabilities (10)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU24466 - Improper input validation CVE-2019-14907 |
CWE-20 | Medium | 0.10.0-4.el7rhgs | 21.01.2020 |
SB2020012110 SB2020012301 SB2020012905 and 10 more |
||
| #VU22329 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2019-10218 |
CWE-22 | Medium | 0.10.0-4.el7rhgs | 29.10.2019 |
SB2019102910 SB2019103005 SB2019110304 and 13 more |
||
| #VU241 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2016-2118 |
CWE-300 | High | 0.9.26-1.el7_1, 0.9.26-1.el6rhs, 0.9.26-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 25 more |
||
| #VU240 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2016-2115 |
CWE-300 | Medium | 0.9.26-1.el7_1, 0.9.26-1.el6rhs, 0.9.26-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 24 more |
||
| #VU239 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2016-2114 |
CWE-300 | Medium | 0.9.26-1.el7_1, 0.9.26-1.el6rhs, 0.9.26-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 11 more |
||
| #VU238 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2016-2113 |
CWE-300 | Medium | 0.9.26-1.el7_1, 0.9.26-1.el6rhs, 0.9.26-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 16 more |
||
| #VU237 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2016-2112 |
CWE-300 | Medium | 0.9.26-1.el7_1, 0.9.26-1.el6rhs, 0.9.26-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 24 more |
||
| #VU236 - Authentication Bypass by Spoofing CVE-2016-2111 |
CWE-290 | Medium | 0.9.26-1.el7_1, 0.9.26-1.el6rhs, 0.9.26-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 25 more |
||
| #VU235 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2016-2110 |
CWE-300 | Medium | 0.9.26-1.el7_1, 0.9.26-1.el6rhs, 0.9.26-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 25 more |
||
| #VU234 - Resource exhaustion CVE-2015-5370 |
CWE-400 | Medium | 0.9.26-1.el7_1, 0.9.26-1.el6rhs, 0.9.26-1.el7rhgs | 29.07.2016 |
SB2016052501 SB2016051803 SB2016050401 and 22 more |