Known vulnerabilities in rh-nodejs14-nodejs (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:rh-nodejs14-nodejs_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 57
Public exploits: 5
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting rh-nodejs14-nodejs (Red Hat package) rh-nodejs14-nodejs (Red Hat package) is affected by 57 known vulnerabilities: 5 high, 48 medium, 4 low Critical High Medium Low

Vulnerabilities (57)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU88175 - Reachable Assertion
CVE-2024-27983
CWE-617 Medium
Available
No
14.21.3-7.el7 05.04.2024 SB2024040526
SB2024040851
SB2024040852
and 56 more
#VU86721 - Improper input validation
CVE-2024-22019
CWE-20 Medium
No
No
14.21.3-6.el7 22.02.2024 SB2024022225
SB2024022226
SB2024022832
and 48 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Available
Exploited
14.21.3-5.el7 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 648 more
#VU76426 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2023-31147
CWE-338 Medium
No
No
14.21.3-4.el7 23.05.2023 SB2023052309
SB2023052312
SB2023053021
and 39 more
#VU76425 - Buffer Underwrite ('Buffer Underflow')
CVE-2023-31130
CWE-124 Low
No
No
14.21.3-4.el7 23.05.2023 SB2023052309
SB2023052312
SB2023053021
and 55 more
#VU76424 - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2023-31124
CWE-338 Medium
No
No
14.21.3-4.el7 23.05.2023 SB2023052309
SB2023052312
SB2023053021
and 33 more
#VU76423 - Improper input validation
CVE-2023-32067
CWE-20 Medium
No
No
14.21.3-4.el7 23.05.2023 SB2023052312
SB2023053021
SB2023060711
and 35 more
#VU76422 - Improper input validation
CVE-2023-32067
CWE-20 Medium
No
No
14.21.3-4.el7 23.05.2023 SB2023052309
SB2023052312
SB2023053021
and 66 more
#VU72750 - Inefficient Algorithmic Complexity
CVE-2022-25881
CWE-407 Medium
No
No
14.21.3-2.el7 03.03.2023 SB2023030326
SB2023030328
SB2023031112
and 61 more
#VU72557 - Memory corruption
CVE-2022-4904
CWE-119 Low
No
No
14.21.3-2.el7 24.02.2023 SB2023022410
SB2023022502
SB2023030233
and 38 more
#VU72400 - Permissions, Privileges, and Access Controls
CVE-2023-23920
CWE-264 Low
No
No
14.21.3-2.el7 20.02.2023 SB2023022020
SB2023030129
SB2023030337
and 55 more
#VU72398 - Permissions, Privileges, and Access Controls
CVE-2023-23918
CWE-264 Medium
No
No
14.21.3-2.el7 20.02.2023 SB2023022020
SB2023030129
SB2023030337
and 48 more
#VU72247 - Improper input validation
CVE-2022-38900
CWE-20 Medium
No
No
14.21.3-2.el7 15.02.2023 SB2023021531
SB2023022714
SB2023032315
and 35 more
#VU69942 - Incorrect Regular Expression
CVE-2022-3517
CWE-185 Medium
No
No
14.21.1-3.el7 06.12.2022 SB2022120638
SB2022120639
SB2022120640
and 48 more
#VU69675 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-24999
CWE-94 Medium
Available
No
14.21.1-3.el7 29.11.2022 SB2022112910
SB2022112911
SB2022112943
and 49 more
#VU69354 - Reliance on Reverse DNS Resolution for a Security-Critical Action
CVE-2022-43548
CWE-350 Medium
No
No
14.21.1-3.el7 15.11.2022 SB2022111599
SB20221115101
SB20221115102
and 47 more
#VU67850 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-35256
CWE-444 Medium
No
No
14.20.1-2.el7 03.10.2022 SB2022100347
SB2022100401
SB2022100402
and 50 more
#VU64030 - Resource exhaustion
CVE-2021-44906
CWE-400 High
No
No
14.20.1-2.el7, 14.21.1-3.el7 07.06.2022 SB2022060836
SB2022062103
SB2022062203
and 52 more
#VU61471 - Exposure of sensitive information to an unauthorized actor
CVE-2022-0235
CWE-200 Low
No
No
14.21.1-3.el7 20.03.2022 SB2022032001
SB2022032002
SB2022032009
and 35 more
#VU55102 - Resource exhaustion
CVE-2021-35065
CWE-400 Medium
No
No
14.21.1-3.el7 21.07.2021 SB2021072101
SB2023020668
SB2023020971
and 24 more


Showing elements 1 - 20 out of 57