Known vulnerabilities in python-pillow (Red Hat package)
Vendor:
Red Hat Inc.
Software:
python-pillow (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:python-pillow_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
67
Public exploits:
3
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
5.1.1-20.el8_6.1
5.1.1-20.el8_8.1
5.1.1-15.el8_4.2
12.3.0-1.el8pc
12.3.0-1.el9pc
5.1.1-23.el8_10
5.1.1-20.el8_6
5.1.1-20.el8_8
5.1.1-22.el8_10
12.2.0-1.el8pc
12.2.0-1.el9pc
12.1.1-1.el8pc
12.1.1-1.el9pc
10.3.0-1.el8pc
10.3.0-1.el9pc
5.1.1-21.el8_10
10.3.0-1.el9ap
5.1.1-20.el8
9.5.0-4.el8pc
10.0.1-1.el9ap
5.1.1-15.el8_4
5.1.1-15.el8_2
5.1.1-19.el8_6
5.1.1-18.el8_9.1
2.0.0-25.gitd1c6db8.el7_9
5.1.1-19.el8_8
2.0.0-24.gitd1c6db8.el7_9
5.1.1-16.el8
5.1.1-14.el8_4
5.1.1-14.el8_2
5.1.1-13.el8_1
5.1.1-18.el8_5
2.0.0-23.gitd1c6db8.el7_9
2.0.0-21.gitd1c6db8.el7
5.1.1-11.el8_0
5.1.1-11.el8_1
5.1.1-12.el8_2
2.0.0-20.gitd1c6db8.el7_7
5.1.1-10.el8_1
5.1.1-10.el8_0
Vulnerabilities (67)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU137006 - Out-of-bounds read CVE-2026-54058 |
CWE-125 | High | 5.1.1-15.el8_4.2, 5.1.1-20.el8_6.1, 5.1.1-20.el8_8.1, 5.1.1-23.el8_10 | 07.07.2026 |
SB2026070342 SB2026071741 SB2026071949 and 12 more |
||
| #VU137005 - Heap-based Buffer Overflow CVE-2026-59197 |
CWE-122 | High | 5.1.1-15.el8_4.2, 5.1.1-20.el8_6.1, 5.1.1-20.el8_8.1, 5.1.1-23.el8_10 | 07.07.2026 |
SB2026041113 SB2026071741 SB2026071949 and 12 more |
||
| #VU136860 - Uncontrolled Memory Allocation CVE-2026-55379 |
CWE-789 | Medium | 5.1.1-15.el8_4.2, 5.1.1-20.el8_6, 5.1.1-20.el8_8, 5.1.1-22.el8_10 | 03.07.2026 |
SB2026070342 SB2026070815 SB2026070816 and 14 more |
||
| #VU136859 - Uncontrolled Memory Allocation CVE-2026-54059 |
CWE-789 | Medium | 5.1.1-15.el8_4.2, 5.1.1-20.el8_6, 5.1.1-20.el8_8, 5.1.1-22.el8_10 | 03.07.2026 |
SB2026070342 SB2026070815 SB2026070816 and 14 more |
||
| #VU136858 - Uncontrolled Memory Allocation CVE-2026-54060 |
CWE-789 | Medium | 5.1.1-15.el8_4.2, 5.1.1-20.el8_6, 5.1.1-20.el8_8, 5.1.1-22.el8_10 | 03.07.2026 |
SB2026070342 SB2026070815 SB2026070816 and 14 more |
||
| #VU136857 - Uncontrolled Memory Allocation CVE-2026-55380 |
CWE-789 | Medium | 5.1.1-15.el8_4.2, 5.1.1-20.el8_6, 5.1.1-20.el8_8, 5.1.1-22.el8_10 | 03.07.2026 |
SB2026070342 SB2026070815 SB2026070816 and 14 more |
||
| #VU105796 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-27610 |
CWE-22 | Medium | 10.3.0-1.el9pc | 17.03.2025 |
SB2025031756 SB20250317118 SB20250317119 and 15 more |
||
| #VU105689 - Improper Control of Generation of Code ('Code Injection') CVE-2025-27407 |
CWE-94 | High | 10.3.0-1.el9pc | 13.03.2025 |
SB2025031315 SB2025031316 SB2025040330 and 3 more |
||
| #VU103000 - Improper input validation CVE-2024-56374 |
CWE-20 | Medium | 10.3.0-1.el9pc | 20.01.2025 |
SB2025012005 SB2025012029 SB2025012030 and 11 more |
||
| #VU101972 - Security Features CVE-2024-56326 |
CWE-254 | Low | 10.3.0-1.el9pc | 27.12.2024 |
SB2024122789 SB2024122790 SB2024122791 and 78 more |
||
| #VU99570 - Exposure of sensitive information to an unauthorized actor CVE-2024-8553 |
CWE-200 | Low | 10.3.0-1.el8pc, 10.3.0-1.el9pc | 31.10.2024 |
SB20241031110 SB2024110111 SB2024110112 and 2 more |
||
| #VU99568 - Missing release of memory after effective lifetime CVE-2024-8376 |
CWE-401 | Medium | 10.3.0-1.el8pc, 10.3.0-1.el9pc | 31.10.2024 |
SB20241031109 SB2024110111 SB2024110112 and 7 more |
||
| #VU97594 - Improper Authentication CVE-2024-7923 |
CWE-287 | High | 10.3.0-1.el8pc, 10.3.0-1.el9pc | 19.09.2024 |
SB2024092064 SB2024092065 SB2024092066 and 1 more |
||
| #VU97593 - Improper Authentication CVE-2024-7012 |
CWE-287 | High | 10.3.0-1.el8pc, 10.3.0-1.el9pc | 19.09.2024 |
SB2024092064 SB2024092065 SB2024092066 and 1 more |
||
| #VU96644 - Improper input validation CVE-2024-7246 |
CWE-20 | Medium | 10.3.0-1.el8pc, 10.3.0-1.el9pc | 30.08.2024 |
SB2024083031 SB2024083036 SB2024090612 and 11 more |
||
| #VU95445 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2024-42005 |
CWE-89 | High | 10.3.0-1.el8pc, 10.3.0-1.el9pc | 07.08.2024 |
SB2024080728 SB2024080771 SB2024080772 and 12 more |
||
| #VU94792 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2024-5569 |
CWE-835 | Medium | 10.3.0-1.el8pc, 10.3.0-1.el9pc | 26.07.2024 |
SB2024072688 SB2024072690 SB2024072692 and 59 more |
||
| #VU94188 - Improper input validation CVE-2024-39614 |
CWE-20 | Medium | 10.3.0-1.el8pc, 10.3.0-1.el9pc | 12.07.2024 |
SB2024071225 SB2024071228 SB2024071229 and 15 more |
||
| #VU94184 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2024-39330 |
CWE-22 | Medium | 10.3.0-1.el8pc, 10.3.0-1.el9pc | 12.07.2024 |
SB2024071225 SB2024071228 SB2024071229 and 13 more |
||
| #VU94183 - Exposure of sensitive information to an unauthorized actor CVE-2024-39329 |
CWE-200 | Medium | 10.3.0-1.el8pc, 10.3.0-1.el9pc | 12.07.2024 |
SB2024071225 SB2024071228 SB2024071229 and 14 more |
Showing elements 1 - 20 out of 67