Known vulnerabilities in oniguruma (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:oniguruma_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 7
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting oniguruma (Red Hat package) oniguruma (Red Hat package) is affected by 7 known vulnerabilities: 3 high, 3 medium, 1 low Critical High Medium Low

Vulnerabilities (7)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU54626 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-3583
CWE-94 High
No
No
6.9.7.1-1.el8ap 08.07.2021 SB2021070822
SB2021070823
SB2021071517
and 12 more
#VU22933 - Buffer over-read
CVE-2019-19204
CWE-126 Medium
No
No
6.8.2-2.1.el8_6, 6.8.2-2.1.el8_8, 6.8.2-2.1.el8_9 22.11.2019 SB2019111806
SB2020120202
SB2022092145
and 23 more
#VU22932 - Buffer over-read
CVE-2019-19203
CWE-126 Medium
No
No
6.8.2-2.1.el8_6, 6.8.2-2.1.el8_8, 6.8.2-2.1.el8_9 22.11.2019 SB2019111806
SB2020120202
SB2022092145
and 22 more
#VU22814 - Integer overflow
CVE-2019-19012
CWE-190 High
No
No
6.8.2-2.1.el8_6, 6.8.2-2.1.el8_8, 6.8.2-2.1.el8_9 18.11.2019 SB2019111806
SB2023021411
SB2024012468
and 19 more
#VU30789 - Resource exhaustion
CVE-2019-16163
CWE-400 Medium
No
No
6.8.2-2.1.el8_6, 6.8.2-2.1.el8_8, 6.8.2-2.1.el8_9 09.09.2019 SB2019090921
SB2022092145
SB2022110232
and 24 more
#VU20906 - NULL Pointer Dereference
CVE-2019-13225
CWE-476 Low
No
No
6.8.2-2.el8 06.09.2019 SB2019090602
SB2019100314
SB2019110720
and 6 more
#VU20904 - Use After Free
CVE-2019-13224
CWE-416 High
No
No
6.8.2-2.1.el8_6, 6.8.2-2.1.el8_8, 6.8.2-2.1.el8_9 06.09.2019 SB2019090602
SB2019092002
SB2019100314
and 26 more