Known vulnerabilities in openchange (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:openchange_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 21
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting openchange (Red Hat package) openchange (Red Hat package) is affected by 21 known vulnerabilities: 3 high, 15 medium, 3 low Critical High Medium Low

Vulnerabilities (21)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU78577 - Out-of-bounds read
CVE-2022-2127
CWE-125 Medium
No
No
2.3-32.el8, 2.3-41.el9 24.07.2023 SB2023072430
SB2023072432
SB2023072433
and 34 more
#VU78576 - Exposure of sensitive information to an unauthorized actor
CVE-2023-34968
CWE-200 Low
No
No
2.3-32.el8, 2.3-41.el9 24.07.2023 SB2023072431
SB2023072432
SB2023072437
and 27 more
#VU78575 - Type confusion
CVE-2023-34967
CWE-843 Medium
No
No
2.3-32.el8, 2.3-41.el9 24.07.2023 SB2023072431
SB2023072432
SB2023072437
and 32 more
#VU78574 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2023-34966
CWE-835 Medium
No
No
2.3-32.el8, 2.3-41.el9 24.07.2023 SB2023072431
SB2023072432
SB2023072437
and 35 more
#VU67583 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2007-4559
CWE-22 High
Available
No
2.3-32.el8, 2.3-41.el9 22.09.2022 SB2007082801
SB2022120206
SB2023060825
and 68 more
#VU67270 - Use of Insufficiently Random Values
CVE-2022-1615
CWE-330 Low
No
No
2.3-31.el8, 2.3-40.el9 13.09.2022 SB2022091371
SB2022091377
SB2022091448
and 18 more
#VU47991 - NULL Pointer Dereference
CVE-2020-14323
CWE-476 Medium
No
No
2.3-27.el8 29.10.2020 SB2020102935
SB2020110205
SB2020110211
and 18 more
#VU47990 - Permissions, Privileges, and Access Controls
CVE-2020-14318
CWE-264 Low
No
No
2.3-27.el8 29.10.2020 SB2020102935
SB2020110205
SB2020110211
and 17 more
#VU45628 - Permissions, Privileges, and Access Controls
CVE-2020-1472
CWE-264 High
Available
Exploited
2.3-27.el8 12.08.2020 SB2020081242
SB2020091810
SB2020092413
and 22 more
#VU34139 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2020-14928
CWE-74 Medium
No
No
2.3-26.el8 17.07.2020 SB2020071733
SB2020110511
SB2020071815
and 6 more
#VU24466 - Improper input validation
CVE-2019-14907
CWE-20 Medium
No
No
2.3-24.el8 21.01.2020 SB2020012110
SB2020012301
SB2020012905
and 10 more
#VU22329 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2019-10218
CWE-22 Medium
No
No
2.3-24.el8 29.10.2019 SB2019102910
SB2019103005
SB2019110304
and 13 more
#VU20809 - Permissions, Privileges, and Access Controls
CVE-2019-10197
CWE-264 Medium
No
No
2.3-24.el8 03.09.2019 SB2019090302
SB2019090424
SB2019090308
and 13 more
#VU240 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2115
CWE-300 Medium
No
No
1.0-1.el6_2, 1.0-5.el6_4, 1.0-7.el6_5, 1.0-7.el6_6 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 24 more
#VU239 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2114
CWE-300 Medium
No
No
1.0-1.el6_2, 1.0-5.el6_4, 1.0-7.el6_5, 1.0-7.el6_6 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 11 more
#VU238 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2113
CWE-300 Medium
No
No
1.0-1.el6_2, 1.0-5.el6_4, 1.0-7.el6_5, 1.0-7.el6_6 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 16 more
#VU237 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2112
CWE-300 Medium
No
No
1.0-1.el6_2, 1.0-5.el6_4, 1.0-7.el6_5, 1.0-7.el6_6 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 24 more
#VU236 - Authentication Bypass by Spoofing
CVE-2016-2111
CWE-290 Medium
No
No
1.0-1.el6_2, 1.0-5.el6_4, 1.0-7.el6_5, 1.0-7.el6_6 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 25 more
#VU235 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2016-2110
CWE-300 Medium
No
No
1.0-1.el6_2, 1.0-5.el6_4, 1.0-7.el6_5, 1.0-7.el6_6 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 25 more
#VU234 - Resource exhaustion
CVE-2015-5370
CWE-400 Medium
No
No
1.0-1.el6_2, 1.0-5.el6_4, 1.0-7.el6_5, 1.0-7.el6_6 29.07.2016 SB2016052501
SB2016051803
SB2016050401
and 22 more


Showing elements 1 - 20 out of 21