Known vulnerabilities in pcs (Red Hat package) - page 2

Software CPE: cpe:2.3:o:red_hat:pcs_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 36
Public exploits: 3
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting pcs (Red Hat package) pcs (Red Hat package) is affected by 36 known vulnerabilities: 5 high, 27 medium, 4 low Critical High Medium Low

Vulnerabilities (36)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU87010 - Incorrect Regular Expression
CVE-2024-25126
CWE-185 Medium
No
No
0.10.4-6.el8_2.5, 0.10.8-1.el8_4.5, 0.10.12-6.el8_6.5, 0.10.15-4.el8_8.2, 0.10.18-2.el8_10, 0.11.1-10.el9_0.5, 0.11.4-7.el9_2.1, 0.11.7-2.el9_4 04.03.2024 SB2024030429
SB2024030544
SB2024041627
and 21 more
#VU75917 - Improper Access Control
CVE-2023-2319
CWE-284 Medium
No
No
0.11.4-7.el9_2 09.05.2023 SB20230509105
#VU74478 - Improper Access Control
CVE-2023-28154
CWE-284 Medium
No
No
0.11.3-4.el9_1.3 05.04.2023 SB2023040511
SB2023040515
SB2023041244
and 9 more
#VU74199 - Improper input validation
CVE-2023-27539
CWE-20 Medium
No
No
0.10.8-1.el8_4.4, 0.10.12-6.el8_6.4, 0.10.15-4.el8_8.1, 0.11.1-10.el9_0.4, 0.11.4-7.el9_2 30.03.2023 SB2023033030
SB2023033041
SB2023041727
and 18 more
#VU73726 - Improper input validation
CVE-2023-27530
CWE-20 Medium
No
No
0.10.8-1.el8_4.4, 0.10.12-6.el8_6.4, 0.10.15-4.el8_8.1, 0.11.1-10.el9_0.4, 0.11.4-7.el9_2 15.03.2023 SB2023031545
SB2023031551
SB2023042535
and 18 more
#VU72247 - Improper input validation
CVE-2022-38900
CWE-20 Medium
No
No
0.11.6-3.el9 15.02.2023 SB2023021531
SB2023022714
SB2023032315
and 35 more
#VU71475 - Download of Code Without Integrity Check
CVE-2022-45442
CWE-494 High
No
No
0.10.2-4.el8_1.3, 0.10.4-6.el8_2.4, 0.10.8-1.el8_4.3, 0.10.12-6.el8_6.3, 0.10.14-5.el8_7.2, 0.11.1-10.el9_0.3, 0.11.3-4.el9_1.2 24.01.2023 SB2023012439
SB2023012441
SB2023012460
and 11 more
#VU67583 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2007-4559
CWE-22 High
Available
No
0.11.6-3.el9 22.09.2022 SB2007082801
SB2022120206
SB2023060825
and 68 more
#VU67056 - Improper Authentication
CVE-2022-1049
CWE-287 Medium
No
No
0.10.14-5.el8, 0.11.3-4.el9 07.09.2022 SB2022090714
SB2022090715
SB2022110836
and 5 more
#VU66985 - Permissions, Privileges, and Access Controls
CVE-2022-2735
CWE-264 Low
No
No
0.10.4-6.el8_2.3, 0.10.8-1.el8_4.2, 0.10.12-6.el8_6.2, 0.11.1-10.el9_0.2 05.09.2022 SB2022090518
SB2022090519
SB2022090520
and 7 more
#VU64863 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-30123
CWE-78 High
No
No
0.9.169-3.el7_9.3 02.07.2022 SB2022070222
SB2022070430
SB2022072530
and 14 more
#VU63415 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-29970
CWE-22 Medium
No
No
0.10.2-4.el8_1.2, 0.10.4-6.el8_2.2, 0.10.8-1.el8_4.1, 0.10.12-6.el8_6.1, 0.11.1-10.el9_0.1 19.05.2022 SB2022051903
SB2022051911
SB2022061573
and 7 more
#VU28228 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-7656
CWE-79 Medium
No
No
0.10.10-4.el8 25.05.2020 SB2020052520
SB2020100907
SB2022072056
and 14 more
#VU27519 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-11023
CWE-79 Low
Available
Exploited
0.10.10-4.el8 05.05.2020 SB2020042126
SB2020052033
SB2020052103
and 180 more
#VU32971 - Improper input validation
CVE-2020-10663
CWE-20 Medium
No
No
0.10.1-4.el8_0.5, 0.10.2-4.el8_1.1, 0.10.4-6.el8_2.1 28.04.2020 SB2020042868
SB2020050208
SB2020081273
and 24 more
#VU18092 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2019-11358
CWE-1321 Low
Available
No
0.9.169-3.el7_9.3 28.03.2019 SB2019032804
SB2019041026
SB2019041801
and 155 more


Showing elements 21 - 40 out of 36