Known vulnerabilities in spice-client-win (Red Hat package)
Vendor:
Red Hat Inc.
Software:
spice-client-win (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:spice-client-win_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
17
Public exploits:
1
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (17)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU122663 - Stack-based buffer overflow CVE-2026-0719 |
CWE-121 | Critical | 8.10-7.el8_2.1, 8.10-7.el8_4.1, 8.10-7.el8_6.1, 8.10-7.el8_8.1, 8.10-7.el8_10 | 11.02.2026 |
SB2026021138 SB2026021139 SB2026021140 and 34 more |
||
| #VU122662 - Stack-based buffer overflow CVE-2026-1761 |
CWE-121 | Critical | 8.10-7.el8_2.1, 8.10-7.el8_4.1, 8.10-7.el8_6.1, 8.10-7.el8_8.1, 8.10-7.el8_10 | 11.02.2026 |
SB2026021138 SB2026021143 SB2026021144 and 33 more |
||
| #VU119956 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2025-14523 |
CWE-444 | Medium | 8.10-6.el8_2.1, 8.10-6.el8_4.1, 8.10-6.el8_6.1, 8.10-6.el8_8.1, 8.10-6.el8_10.1 | 15.12.2025 |
SB2025121511 SB2026011201 SB2026011202 and 36 more |
||
| #VU116196 - Memory corruption CVE-2025-9900 |
CWE-119 | High | 8.10-3.el8_2.1, 8.10-3.el8_4.1, 8.10-3.el8_6.1, 8.10-3.el8_8.1 | 30.09.2025 |
SB2025093033 SB2025093035 SB2025100921 and 50 more |
||
| #VU115751 - Resource exhaustion CVE-2025-59375 |
CWE-400 | Medium | 8.10-3.el8_2.1, 8.10-3.el8_4.1, 8.10-3.el8_6.1, 8.10-3.el8_8.1 | 17.09.2025 |
SB2025091783 SB2025091789 SB2025091790 and 109 more |
||
| #VU113649 - Use After Free CVE-2025-8176 |
CWE-416 | High | 8.10-3.el8_2.1, 8.10-3.el8_4.1, 8.10-3.el8_6.1, 8.10-3.el8_8.1 | 05.08.2025 |
SB2025080553 SB2025080555 SB2025081259 and 21 more |
||
| #VU113156 - Memory corruption CVE-2025-6965 |
CWE-119 | Medium | 8.10-3.el8_2.1, 8.10-3.el8_4.1, 8.10-3.el8_6.1, 8.10-3.el8_8.1 | 22.07.2025 |
SB2025072254 SB2025072807 SB2025072890 and 100 more |
||
| #VU109941 - Resource exhaustion CVE-2025-32907 |
CWE-400 | Medium | 8.10-1.el8_10 | 29.05.2025 |
SB2025052993 SB2025052994 SB2025052995 and 27 more |
||
| #VU109939 - NULL Pointer Dereference CVE-2025-32909 |
CWE-476 | Low | 8.10-1.el8_10 | 29.05.2025 |
SB2025052718 SB2025052994 SB2025052995 and 14 more |
||
| #VU109936 - Use After Free CVE-2025-32911 |
CWE-416 | High | 8.10-1.el8_10 | 29.05.2025 |
SB2025052992 SB2025052997 SB2025052998 and 33 more |
||
| #VU109935 - NULL Pointer Dereference CVE-2025-32910 |
CWE-476 | Low | 8.10-1.el8_10 | 29.05.2025 |
SB2025052992 SB2025052997 SB2025052998 and 11 more |
||
| #VU109931 - Buffer over-read CVE-2025-32050 |
CWE-126 | Medium | 8.10-1.el8_10 | 29.05.2025 |
SB2024111329 SB2025052980 SB2025052994 and 28 more |
||
| #VU109929 - Buffer over-read CVE-2025-32052 |
CWE-126 | Medium | 8.10-1.el8_10 | 29.05.2025 |
SB2024111329 SB2025052980 SB2025052994 and 32 more |
||
| #VU109927 - Buffer over-read CVE-2025-32053 |
CWE-126 | Medium | 8.10-1.el8_10 | 29.05.2025 |
SB2024111329 SB2025052980 SB2025052994 and 29 more |
||
| #VU109838 - NULL Pointer Dereference CVE-2025-32913 |
CWE-476 | High | 8.10-1.el8_10 | 27.05.2025 |
SB2025052718 SB2025052723 SB2025052997 and 33 more |
||
| #VU109834 - Out-of-bounds read CVE-2025-32906 |
CWE-125 | Medium | 8.10-1.el8_10 | 27.05.2025 |
SB2025052715 SB2025052723 SB2025052994 and 37 more |
||
| #VU105715 - Out-of-bounds write CVE-2025-27363 |
CWE-787 | Critical | 8.2-1.el8_2, 8.4-2.el8_4, 8.6-1.el8_6, 8.8-5.el8_8, 8.10-1.el8_10 | 14.03.2025 |
SB2025031402 SB2025031502 SB2025031750 and 97 more |