Known vulnerabilities in nss-softokn (Red Hat package)
Vendor:
Red Hat Inc.
Software:
nss-softokn (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:nss-softokn_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
13
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
3.112.0-8.el9_4
3.44.0-9.el7_7
3.36.0-7.el7_6
3.28.3-10.el7_4
3.53.1-6.el7_9
3.36.0-6.el7_6
3.28.3-9.el7_4
3.36.0-6.el7_5
3.14.3-23.el6_6
3.44.0-8.el7_7
3.44.0-5.el7
3.16.2-1.el7_0
3.16.2-2.el7_0
3.12.9-12.el6_2
3.16.2.3-9.el7
3.16.2.3-13.el7_1
3.16.2.3-14.2.el7_2
3.44.0-6.el6_10
3.44.0-5.el6_10
3.14.3-23.el6_7
3.14.3-22.el6_6
3.14.3-19.el6_6
3.14.3-18.el6_6
3.14.3-17.el6
3.14.3-12.el6_5
3.14.3-10.el6_5
3.14.3-9.el6
3.14.3-4.el6_4
3.14.3-3.el6_4
3.12.9-11.el6
3.12.9-3.el6
3.12.8-1.el6_0
Vulnerabilities (13)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU47197 - Heap-based Buffer Overflow CVE-2019-17006 |
CWE-122 | High | 3.28.3-10.el7_4, 3.36.0-7.el7_6, 3.44.0-9.el7_7, 3.53.1-6.el7_9 | 30.09.2020 |
SB2019090221 SB2020093089 SB2020062437 and 19 more |
||
| #VU46019 - Cryptographic Issues CVE-2020-6829 |
CWE-310 | Low | 3.53.1-6.el7_9 | 25.08.2020 |
SB2020082520 SB2020072974 SB2020072975 and 18 more |
||
| #VU45799 - Out-of-bounds read CVE-2020-12403 |
CWE-125 | Medium | 3.28.3-10.el7_4, 3.36.0-7.el7_6, 3.44.0-9.el7_7, 3.53.1-6.el7_9 | 20.08.2020 |
SB2020082004 SB2020082005 SB2020072966 and 17 more |
||
| #VU45798 - Use of a Broken or Risky Cryptographic Algorithm CVE-2020-12401 |
CWE-327 | Low | 3.53.1-6.el7_9 | 20.08.2020 |
SB2020082004 SB2020082005 SB2020072965 and 19 more |
||
| #VU45797 - Use of a Broken or Risky Cryptographic Algorithm CVE-2020-12400 |
CWE-327 | Low | 3.53.1-6.el7_9 | 20.08.2020 |
SB2020082004 SB2020082005 SB2020072964 and 19 more |
||
| #VU29460 - Cryptographic Issues CVE-2020-12402 |
CWE-310 | Low | 3.53.1-6.el7_9 | 02.07.2020 |
SB2020070208 SB2020071322 SB2020071401 and 23 more |
||
| #VU24061 - Selection of Less-Secure Algorithm During Negotiat CVE-2019-17023 |
CWE-757 | Low | 3.53.1-6.el7_9 | 07.01.2020 |
SB2020010708 SB2020010807 SB2020010712 and 13 more |
||
| #VU23467 - Improper input validation CVE-2019-17007 |
CWE-20 | Medium | 3.36.0-7.el7_6 | 09.12.2019 |
SB2019112801 SB2019120912 SB2019120913 and 4 more |
||
| #VU23369 - Use After Free CVE-2019-11756 |
CWE-416 | High | 3.28.3-10.el7_4, 3.36.0-7.el7_6, 3.44.0-9.el7_7, 3.53.1-6.el7_9 | 03.12.2019 |
SB2019120312 SB2019120314 SB2019121002 and 16 more |
||
| #VU23050 - Out-of-bounds write CVE-2019-11745 |
CWE-787 | High | 3.28.3-9.el7_4, 3.36.0-6.el7_5, 3.36.0-6.el7_6 | 28.11.2019 |
SB2019112801 SB2019112802 SB2019120312 and 29 more |
||
| #VU33037 - Out-of-bounds read CVE-2019-11719 |
CWE-125 | Medium | 3.53.1-6.el7_9 | 23.07.2019 |
SB2019072322 SB2019082322 SB2019073024 and 17 more |
||
| #VU47195 - Improper Certificate Validation CVE-2019-11727 |
CWE-295 | Medium | 3.53.1-6.el7_9 | 23.07.2019 |
SB2020093089 SB2020011201 SB2021043017 and 8 more |
||
| #VU13370 - Exposure of sensitive information to an unauthorized actor CVE-2018-0495 |
CWE-200 | Low | 3.28.3-9.el7_4, 3.36.0-6.el7_5, 3.36.0-6.el7_6 | 16.06.2018 |
SB2018061705 SB2018061412 SB2018061801 and 22 more |