Known vulnerabilities in rpm (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:rpm_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 6
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting rpm (Red Hat package) rpm (Red Hat package) is affected by 6 known vulnerabilities: 2 medium, 4 low Critical High Medium Low

Vulnerabilities (6)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU79523 - Improper Link Resolution Before File Access ('Link Following')
CVE-2021-35939
CWE-59 Low
No
No
4.14.3-26.el8_6, 4.14.3-28.el8_8, 4.14.3-28.el8_9, 4.16.1.3-14.el9_0.1, 4.16.1.3-27.el9_3 15.08.2023 SB2023081530
SB2024012452
SB2024012458
and 45 more
#VU79522 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2021-35937
CWE-367 Low
No
No
4.14.3-26.el8_6, 4.14.3-28.el8_8, 4.14.3-28.el8_9, 4.16.1.3-14.el9_0.1, 4.16.1.3-27.el9_3 15.08.2023 SB2023081530
SB2024012452
SB2024012458
and 45 more
#VU79521 - Improper Link Resolution Before File Access ('Link Following')
CVE-2021-35938
CWE-59 Low
No
No
4.14.3-26.el8_6, 4.14.3-28.el8_8, 4.14.3-28.el8_9, 4.16.1.3-14.el9_0.1, 4.16.1.3-27.el9_3 15.08.2023 SB2023081530
SB2024012452
SB2024012458
and 45 more
#VU59993 - Improper Verification of Cryptographic Signature
CVE-2021-3521
CWE-347 Medium
No
No
4.14.2-40.el8_2, 4.14.3-14.el8_4.2, 4.14.3-19.el8_5.2 25.01.2022 SB2022012518
SB2022012519
SB2022020935
and 23 more
#VU54478 - Out-of-bounds read
CVE-2021-20266
CWE-125 Low
No
No
4.14.3-19.el8 30.06.2021 SB2021063035
SB2021072003
SB2021111133
and 16 more
#VU54477 - Insufficient Verification of Data Authenticity
CVE-2021-20271
CWE-345 Medium
No
No
4.11.3-35.el7_6.2, 4.11.3-40.el7_7.1, 4.11.3-48.el7_9, 4.14.2-38.el8_2, 4.14.3-14.el8_4 30.06.2021 SB2021063035
SB2021063038
SB2021071302
and 34 more