Known vulnerabilities in rh-nodejs10-nodejs (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:rh-nodejs10-nodejs_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 17
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting rh-nodejs10-nodejs (Red Hat package) rh-nodejs10-nodejs (Red Hat package) is affected by 17 known vulnerabilities: 3 high, 12 medium, 2 low Critical High Medium Low

Vulnerabilities (17)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU76389 - Incorrect Regular Expression
CVE-2020-7754
CWE-185 Medium
No
No
10.23.1-2.el7 19.05.2023 SB2023051950
SB2022072231
SB2021020440
and 5 more
#VU66955 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-7788
CWE-94 Medium
No
No
10.23.1-2.el7 05.09.2022 SB2020121120
SB2022090501
SB2022091209
and 21 more
#VU55498 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-15366
CWE-94 Medium
No
No
10.23.1-2.el7 02.08.2021 SB2020071552
SB2021080213
SB2020120120
and 14 more
#VU52909 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-7774
CWE-94 Medium
No
No
10.23.1-2.el7 06.05.2021 SB2020111735
SB2021050615
SB2021092814
and 24 more
#VU50955 - Reliance on Reverse DNS Resolution for a Security-Critical Action
CVE-2021-22884
CWE-350 Medium
No
No
10.24.0-1.el7 25.02.2021 SB2021022530
SB2021022532
SB2021022616
and 38 more
#VU50954 - Resource Management Errors
CVE-2021-22883
CWE-399 Medium
No
No
10.24.0-1.el7 25.02.2021 SB2021022530
SB2021022532
SB2021022614
and 36 more
#VU49254 - Use After Free
CVE-2020-8265
CWE-416 Medium
No
No
10.23.1-2.el7 04.01.2021 SB2021010419
SB2021010704
SB2021010705
and 33 more
#VU49253 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-8287
CWE-444 Medium
Available
No
10.23.1-2.el7 04.01.2021 SB2021010419
SB2021010706
SB2021010707
and 33 more
#VU47248 - Buffer overflow
CVE-2020-8252
CWE-120 High
No
No
10.23.1-2.el7 18.09.2020 SB2020100117
SB2020091824
SB2020091825
and 19 more
#VU47355 - Information Exposure Through Log Files
CVE-2020-15095
CWE-532 Low
No
No
10.23.1-2.el7 07.07.2020 SB2020070743
SB2020100608
SB2020101002
and 12 more
#VU28539 - Memory corruption
CVE-2020-8174
CWE-119 High
No
No
10.21.0-3.el7 03.06.2020 SB2020060305
SB2020060607
SB2020072216
and 20 more
#VU28538 - Resource exhaustion
CVE-2020-11080
CWE-400 Medium
No
No
10.21.0-3.el7 03.06.2020 SB2020060305
SB2020060607
SB2020060703
and 42 more
#VU26304 - Resource exhaustion
CVE-2020-7608
CWE-400 Medium
No
No
10.23.1-2.el7 23.03.2020 SB2020032303
SB2023011262
SB2024022730
and 4 more
#VU26151 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-7598
CWE-94 Medium
No
No
10.21.0-3.el7 18.03.2020 SB2020031805
SB2020072216
SB2020061308
and 18 more
#VU26149 - Integer overflow
CVE-2020-10531
CWE-190 High
No
No
10.21.0-3.el7 17.03.2020 SB2020031801
SB2020031802
SB2020031803
and 40 more
#VU24833 - Resource exhaustion
CVE-2020-8116
CWE-400 Medium
No
No
10.23.1-2.el7 03.02.2020 SB2020020307
SB2020101915
SB2020110420
and 4 more
#VU14493 - Exposure of sensitive information to an unauthorized actor
CVE-2018-7166
CWE-200 Low
No
No
10.10.0-3.el7 21.08.2018 SB2018082209
SB2019041743