Known vulnerabilities in mingw-expat (Red Hat package)
Vendor:
Red Hat Inc.
Software:
mingw-expat (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:mingw-expat_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
9
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (9)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU115751 - Resource exhaustion CVE-2025-59375 |
CWE-400 | Medium | 2.5.0-1.el8_10 | 17.09.2025 |
SB2025091783 SB2025091789 SB2025091790 and 106 more |
||
| #VU67532 - Use After Free CVE-2022-40674 |
CWE-416 | High | 2.4.8-2.el8 | 21.09.2022 |
SB2022092118 SB2022092119 SB2022092317 and 111 more |
||
| #VU60739 - Integer overflow CVE-2022-25315 |
CWE-190 | High | 2.4.8-1.el8 | 21.02.2022 |
SB2022022109 SB2022022113 SB2022022411 and 99 more |
||
| #VU60738 - Integer overflow CVE-2022-25314 |
CWE-190 | Medium | 2.4.8-1.el8 | 21.02.2022 |
SB2022022109 SB2022022113 SB2022022411 and 68 more |
||
| #VU60737 - Stack-based buffer overflow CVE-2022-25313 |
CWE-121 | High | 2.4.8-1.el8 | 21.02.2022 |
SB2022022109 SB2022022113 SB2022022411 and 64 more |
||
| #VU60736 - Improper Control of Generation of Code ('Code Injection') CVE-2022-25235 |
CWE-94 | High | 2.4.8-1.el8 | 21.02.2022 |
SB2022022109 SB2022022113 SB2022022411 and 106 more |
||
| #VU60733 - Improper input validation CVE-2022-25236 |
CWE-20 | Medium | 2.4.8-1.el8 | 21.02.2022 |
SB2022022109 SB2022022113 SB2022022411 and 109 more |
||
| #VU60114 - Integer overflow CVE-2022-23990 |
CWE-190 | High | 2.4.8-1.el8 | 28.01.2022 |
SB2022012504 SB2022012804 SB2022020902 and 46 more |
||
| #VU18923 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2018-20843 |
CWE-611 | Medium | 2.2.4-5.el8 | 27.06.2019 |
SB2019062808 SB2019070104 SB2019072102 and 30 more |