Known vulnerabilities in python3.9 (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:python3.9_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 16
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting python3.9 (Red Hat package) python3.9 (Red Hat package) is affected by 16 known vulnerabilities: 2 high, 10 medium, 4 low Critical High Medium Low

Vulnerabilities (16)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU100516 - Improper input validation
CVE-2024-11168
CWE-20 Medium
No
No
3.9.21-1.el9_5 15.11.2024 SB2024111507
SB2024111526
SB2024111527
and 76 more
#VU99357 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-9287
CWE-78 Low
No
No
3.9.18-3.el9_4.7, 3.9.21-1.el9_5 28.10.2024 SB2024102836
SB2024102838
SB20241101111
and 117 more
#VU96745 - Incorrect Regular Expression
CVE-2024-6232
CWE-185 Medium
No
No
3.9.10-4.el9_0.6, 3.9.16-1.el9_2.8, 3.9.18-3.el9_4.6, 3.9.19-8.el9_5.1 03.09.2024 SB2024090377
SB2024090927
SB2024091048
and 145 more
#VU96596 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2024-8088
CWE-835 Medium
No
No
3.9.19-8.el9 28.08.2024 SB2024082860
SB2024082861
SB2024082862
and 82 more
#VU95571 - Command injection
CVE-2024-6923
CWE-77 Medium
No
No
3.9.16-1.el9_2.8 08.08.2024 SB2024080861
SB2024080862
SB2024080863
and 144 more
#VU87685 - Resource exhaustion
CVE-2024-0450
CWE-400 Medium
No
No
3.9.18-3.el9_4.1 21.03.2024 SB2024032107
SB2024032110
SB2024040848
and 80 more
#VU87185 - UNIX Symbolic Link (Symlink) Following
CVE-2023-6597
CWE-61 Low
No
No
3.9.10-4.el9_0.4, 3.9.16-1.el9_2.5, 3.9.18-3.el9_4.1 07.03.2024 SB2024030718
SB2024030726
SB2024030727
and 88 more
#VU82980 - Improper input validation
CVE-2023-27043
CWE-20 Medium
No
No
3.9.16-1.el9_2.3, 3.9.18-1.el9_3.1 10.11.2023 SB2023041957
SB2023111064
SB2023111315
and 120 more
#VU80228 - Cleartext Transmission of Sensitive Information
CVE-2023-40217
CWE-319 Medium
No
No
3.9.10-4.el9_0.2, 3.9.16-1.el9_2.2 01.09.2023 SB2023090142
SB2023090143
SB2023090144
and 139 more
#VU72618 - Improper input validation
CVE-2023-24329
CWE-20 Medium
No
No
3.9.10-4.el9_0.1, 3.9.16-1.el9_2.1 28.02.2023 SB2023022819
SB2023022822
SB2023030832
and 158 more
#VU69392 - Resource exhaustion
CVE-2022-45061
CWE-400 Medium
No
No
3.9.14-1.el9_1.2 16.11.2022 SB2022111650
SB2022112824
SB2022112856
and 125 more
#VU69391 - Deserialization of Untrusted Data
CVE-2022-42919
CWE-502 Low
No
No
3.9.10-4.el9_0 16.11.2022 SB2022111649
SB2022111655
SB2022111656
and 35 more
#VU67760 - Type conversion
CVE-2020-10735
CWE-704 Medium
No
No
3.9.10-3.el9_0 29.09.2022 SB2022092968
SB2022092970
SB2022093032
and 86 more
#VU67591 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2021-28861
CWE-601 Low
No
No
3.9.14-1.el9 22.09.2022 SB2022092243
SB2022092244
SB2022093032
and 76 more
#VU67583 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2007-4559
CWE-22 High
Available
No
3.9.18-1.el9_3 22.09.2022 SB2007082801
SB2022120206
SB2023060825
and 68 more
#VU64573 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2015-20107
CWE-78 High
No
No
3.9.14-1.el9 22.06.2022 SB2022062206
SB2022062207
SB2022062436
and 85 more