Known vulnerabilities in runc (Red Hat package) - page 8

Software CPE: cpe:2.3:o:red_hat:runc_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 171
Public exploits: 9
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting runc (Red Hat package) runc (Red Hat package) is affected by 171 known vulnerabilities: 9 high, 112 medium, 50 low Critical High Medium Low

Vulnerabilities (171)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU53436 - Exposure of sensitive information to an unauthorized actor
CVE-2021-25737
CWE-200 Low
No
No
1.0.0-98.rhaos4.8.gitcd80260.el7, 1.0.0-98.rhaos4.8.gitcd80260.el8 24.05.2021 SB2021052409
SB2021060911
SB2021090126
and 4 more
#VU53399 - Security Features
CVE-2021-30465
CWE-254 Low
No
No
1.0.0-69.rc10.el7_9, 1.0.0-74.rhaos4.5.gitd2c3b70.el7, 1.0.0-74.rhaos4.5.gitd2c3b70.el8, 1.0.0-87.rhaos4.6.git23384e2.el7, 1.0.0-87.rhaos4.6.git23384e2.el8, 1.0.0-96.rhaos4.8.gitcd80260.el7, 1.0.0-96.rhaos4.8.gitcd80260.el8 20.05.2021 SB2021052013
SB2021052014
SB2021052015
and 33 more
#VU51878 - Exposure of sensitive information to an unauthorized actor
CVE-2021-28163
CWE-200 Medium
No
No
1.0.0-95.rhaos4.8.gitcd80260.el7, 1.0.0-95.rhaos4.8.gitcd80260.el8 01.04.2021 SB2021040179
SB2021050704
SB2021051321
and 27 more
#VU51876 - Resource exhaustion
CVE-2021-28165
CWE-400 Medium
No
No
1.0.0-95.rhaos4.8.gitcd80260.el7, 1.0.0-95.rhaos4.8.gitcd80260.el8 01.04.2021 SB2021040179
SB2021042208
SB2021050704
and 56 more
#VU50047 - Incorrect Calculation
CVE-2021-3114
CWE-682 Medium
No
No
1.0.0-95.rhaos4.8.gitcd80260.el7, 1.0.0-95.rhaos4.8.gitcd80260.el8, 1.0.0-98.rhaos4.8.gitcd80260.el7, 1.0.0-98.rhaos4.8.gitcd80260.el8 26.01.2021 SB2021012714
SB2021012715
SB20210120130
and 40 more
#VU50020 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2021-21615
CWE-367 Medium
No
No
1.0.0-72.rhaos4.5.giteadfc6b.el8, 1.0.0-82.rhaos4.6.git086e841.el7, 1.0.0-82.rhaos4.6.git086e841.el8 26.01.2021 SB2021012623
SB2021021723
SB2021022601
and 1 more
#VU49525 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21611
CWE-79 Low
No
No
1.0.0-72.rhaos4.5.giteadfc6b.el8, 1.0.0-82.rhaos4.6.git086e841.el7, 1.0.0-82.rhaos4.6.git086e841.el8 14.01.2021 SB2021011418
SB2021011453
SB2021012106
and 2 more
#VU49524 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21610
CWE-79 Low
No
No
1.0.0-72.rhaos4.5.giteadfc6b.el8, 1.0.0-82.rhaos4.6.git086e841.el7, 1.0.0-82.rhaos4.6.git086e841.el8 14.01.2021 SB2021011418
SB2021011452
SB2021012106
and 2 more
#VU49523 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21608
CWE-79 Low
No
No
1.0.0-72.rhaos4.5.giteadfc6b.el8, 1.0.0-82.rhaos4.6.git086e841.el7, 1.0.0-82.rhaos4.6.git086e841.el8 14.01.2021 SB2021011418
SB2021011450
SB2021012106
and 2 more
#VU49522 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21603
CWE-79 Low
No
No
1.0.0-72.rhaos4.5.giteadfc6b.el8, 1.0.0-82.rhaos4.6.git086e841.el7, 1.0.0-82.rhaos4.6.git086e841.el8 13.01.2021 SB2021011418
SB2021011445
SB2021012106
and 2 more
#VU49526 - XML Injection
CVE-2021-21604
CWE-91 Medium
No
No
1.0.0-72.rhaos4.5.giteadfc6b.el8, 1.0.0-82.rhaos4.6.git086e841.el7, 1.0.0-82.rhaos4.6.git086e841.el8 13.01.2021 SB2021011418
SB2021011446
SB2021012106
and 2 more
#VU49527 - Exposure of sensitive information to an unauthorized actor
CVE-2021-21602
CWE-200 Medium
No
No
1.0.0-72.rhaos4.5.giteadfc6b.el8, 1.0.0-82.rhaos4.6.git086e841.el7, 1.0.0-82.rhaos4.6.git086e841.el8 13.01.2021 SB2021011418
SB2021011444
SB2021012106
and 2 more
#VU49528 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-21605
CWE-22 Medium
No
No
1.0.0-72.rhaos4.5.giteadfc6b.el8, 1.0.0-82.rhaos4.6.git086e841.el7, 1.0.0-82.rhaos4.6.git086e841.el8 13.01.2021 SB2021011418
SB2021011447
SB2021012106
and 2 more
#VU49529 - Permissions, Privileges, and Access Controls
CVE-2021-21606
CWE-264 Low
No
No
1.0.0-72.rhaos4.5.giteadfc6b.el8, 1.0.0-82.rhaos4.6.git086e841.el7, 1.0.0-82.rhaos4.6.git086e841.el8 13.01.2021 SB2021011418
SB2021011448
SB2021012106
and 2 more
#VU49530 - Memory corruption
CVE-2021-21607
CWE-119 Medium
No
No
1.0.0-72.rhaos4.5.giteadfc6b.el8, 1.0.0-82.rhaos4.6.git086e841.el7, 1.0.0-82.rhaos4.6.git086e841.el8 13.01.2021 SB2021011418
SB2021011449
SB2021012106
and 2 more
#VU49531 - Permissions, Privileges, and Access Controls
CVE-2021-21609
CWE-264 Low
No
No
1.0.0-72.rhaos4.5.giteadfc6b.el8, 1.0.0-82.rhaos4.6.git086e841.el7, 1.0.0-82.rhaos4.6.git086e841.el8 13.01.2021 SB2021011418
SB2021011451
SB2021012106
and 2 more
#VU48480 - Improper input validation
CVE-2020-28362
CWE-20 Medium
No
No
1.0.0-95.rhaos4.8.gitcd80260.el7, 1.0.0-95.rhaos4.8.gitcd80260.el8 17.11.2020 SB2020111715
SB2020111716
SB2020111225
and 30 more
#VU27924 - Incorrect Default Permissions
CVE-2020-1945
CWE-276 Low
No
No
1.0.0-72.rhaos4.5.giteadfc6b.el8, 1.0.0-82.rhaos4.6.git086e841.el7, 1.0.0-82.rhaos4.6.git086e841.el8 15.05.2020 SB2020051501
SB2020052114
SB2020060205
and 48 more
#VU47428 - Permissions, Privileges, and Access Controls
CVE-2020-11979
CWE-264 Low
No
No
1.0.0-72.rhaos4.5.giteadfc6b.el8, 1.0.0-82.rhaos4.6.git086e841.el7, 1.0.0-82.rhaos4.6.git086e841.el8 14.05.2020 SB2020100804
SB2020100815
SB2020111614
and 51 more
#VU26412 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2019-11236
CWE-93 Medium
Available
No
1.0.0-69.rhaos4.4.git81f3917.el7, 1.0.0-69.rhaos4.4.git81f3917.el8 26.03.2020 SB2020032626
SB2020031827
SB2019091504
and 36 more


Showing elements 141 - 160 out of 171