Known vulnerabilities in toolbox (Red Hat package)
Vendor:
Red Hat Inc.
Software:
toolbox (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:toolbox_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
107
Public exploits:
7
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
0.0.99.5-5.rhaos4.18.el8
0.0.99.5.1-2.el9_4
0.0.99.4.1-1.el9_2
0.2-1.el10_0
0.2-1.el9_6
0.0.99.5-3.rhaos4.18.el8
0.0.99.5-5.el9
0.1.0-3.rhaos4.17.el8
0.1.2-1.rhaos4.17.el9
0.1.0-2.rhaos4.16.el8
0.1.2-1.rhaos4.16.el9
0.0.99.5-2.el9
0.1.0-2.rhaos4.14.el8
0.1.2-1.rhaos4.15.el9
0.0.99.4-6.el9_3
0.1.2-1.rhaos4.14.el9
0.0.99.3-10.el9_2
0.0.99.3-4.el9_0
0.1.2-1.rhaos4.13.el9
0.0.99.3-9.el9
0.0.9-1.rhaos4.10.el8
0.1.1-1.rhaos4.11.el8
0.1.1-3.rhaos4.12.el8
0.0.9-1.rhaos4.11.el8
0.0.8-3.rhaos4.7.el8
0.0.8-1.rhaos4.6.el8
0.1.0-1.rhaos4.12.el8
0.0.99.3-5.el9
0.0.8-4.rhaos4.10.el8
0.0.8-3.rhaos4.9.el8
0.0.8-3.rhaos4.8.el8
0.0.5-1.rhaos4.2.el8
0.0.7-1.rhaos4.3.el8
0.0.6-1.rhaos4.3.el8
0.0.3-1.el8
Vulnerabilities (107)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU124034 - Resource exhaustion CVE-2025-61726 |
CWE-400 | Medium | 0.0.99.5-5.rhaos4.18.el8 | 16.03.2026 |
SB2026031636 SB2026031637 SB2026031638 and 143 more |
||
| #VU121565 - Resource exhaustion CVE-2025-65637 |
CWE-400 | Medium | 0.0.99.4.1-1.el9_2, 0.0.99.5.1-2.el9_4 | 15.01.2026 |
SB2026011525 SB20260116132 SB2026011920 and 35 more |
||
| #VU118190 - Resource exhaustion CVE-2025-58183 |
CWE-400 | Medium | 0.0.99.5-5.rhaos4.18.el8 | 07.11.2025 |
SB2025110705 SB2025110725 SB2025110726 and 177 more |
||
| #VU113763 - Untrusted Search Path CVE-2025-23266 |
CWE-426 | Low | 0.2-1.el9_6, 0.2-1.el10_0 | 07.08.2025 |
SB2025080772 SB2025080773 SB2025081001 and 4 more |
||
| #VU107019 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2025-22871 |
CWE-444 | Medium | 0.0.99.5-3.rhaos4.18.el8 | 05.04.2025 |
SB2025040507 SB2025040508 SB2025040739 and 109 more |
||
| #VU94616 - Information Exposure Through Log Files CVE-2024-6104 |
CWE-532 | Low | 0.1.0-3.rhaos4.17.el8, 0.1.2-1.rhaos4.17.el9 | 19.07.2024 |
SB2024071927 SB2024071929 SB2024071930 and 83 more |
||
| #VU93850 - Resource exhaustion CVE-2024-24791 |
CWE-400 | Medium | 0.0.99.5-5.el9 | 07.07.2024 |
SB2024070727 SB2024070728 SB2024070729 and 86 more |
||
| #VU91159 - Improper input validation CVE-2024-24789 |
CWE-20 | Low | 0.1.0-3.rhaos4.17.el8, 0.1.2-1.rhaos4.17.el9 | 05.06.2024 |
SB2024060520 SB2024060635 SB2024060729 and 78 more |
||
| #VU89685 - Improper Validation of Integrity Check Value CVE-2024-3727 |
CWE-354 | Medium | 0.1.0-2.rhaos4.16.el8, 0.1.2-1.rhaos4.16.el9 | 21.05.2024 |
SB2024052112 SB2024052116 SB2024052117 and 68 more |
||
| #VU89296 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2024-24788 |
CWE-835 | Medium | 0.0.99.5-5.el9 | 09.05.2024 |
SB2024050936 SB2024050937 SB2024051029 and 43 more |
||
| #VU87830 - Missing release of memory after effective lifetime CVE-2024-1394 |
CWE-401 | Medium | 0.1.0-2.rhaos4.16.el8, 0.1.2-1.rhaos4.16.el9 | 26.03.2024 |
SB2024032646 SB2024032647 SB2024032648 and 54 more |
||
| #VU87329 - Resource exhaustion CVE-2024-28176 |
CWE-400 | Medium | 0.1.0-2.rhaos4.16.el8, 0.1.2-1.rhaos4.16.el9 | 11.03.2024 |
SB2024031123 SB2024031446 SB2024031447 and 37 more |
||
| #VU87201 - Improper input validation CVE-2024-24784 |
CWE-20 | Medium | 0.1.0-2.rhaos4.16.el8, 0.1.2-1.rhaos4.16.el9 | 07.03.2024 |
SB2024030734 SB2024030750 SB2024030752 and 48 more |
||
| #VU87200 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-24785 |
CWE-79 | Low | 0.0.99.5-5.el9, 0.1.0-2.rhaos4.16.el8, 0.1.2-1.rhaos4.16.el9 | 07.03.2024 |
SB2024030734 SB2024030750 SB2024030752 and 61 more |
||
| #VU87198 - Exposure of sensitive information to an unauthorized actor CVE-2023-45289 |
CWE-200 | Low | 0.1.0-2.rhaos4.16.el8, 0.1.2-1.rhaos4.16.el9 | 07.03.2024 |
SB2024030734 SB2024030750 SB2024030752 and 54 more |
||
| #VU87197 - Resource exhaustion CVE-2023-45290 |
CWE-400 | Medium | 0.0.99.5-5.el9, 0.1.0-2.rhaos4.16.el8, 0.1.2-1.rhaos4.16.el9 | 07.03.2024 |
SB2024030734 SB2024030750 SB2024030752 and 101 more |
||
| #VU87196 - Error Handling CVE-2024-24783 |
CWE-388 | Medium | 0.1.0-2.rhaos4.16.el8, 0.1.2-1.rhaos4.16.el9 | 07.03.2024 |
SB2024030734 SB2024030750 SB2024030752 and 81 more |
||
| #VU86795 - Improper input validation CVE-2023-29483 |
CWE-20 | Medium | 0.1.0-2.rhaos4.16.el8, 0.1.2-1.rhaos4.16.el9 | 26.02.2024 |
SB2024022638 SB2024040115 SB2024042448 and 37 more |
||
| #VU80573 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-39319 |
CWE-79 | Medium | 0.0.99.5-2.el9, 0.1.2-1.rhaos4.14.el9 | 08.09.2023 |
SB2023090845 SB2023091146 SB2023091875 and 62 more |
||
| #VU80572 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-39318 |
CWE-79 | Medium | 0.0.99.5-2.el9, 0.1.2-1.rhaos4.14.el9 | 08.09.2023 |
SB2023090845 SB2023091146 SB2023091875 and 61 more |
Showing elements 1 - 20 out of 107