Known vulnerabilities in dracut-saltboot - page 2
Vendor:
SUSE
Software:
dracut-saltboot
Software CPE:
cpe:2.3:o:suse:dracut-saltboot:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
83
Public exploits:
6
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.4
Breakdown by Severity Chart
1.2.1-150002.3.9.1
1.1.0-159000.2.2.1
1.1.0-150000.1.65.1
1.1.0-150002.3.6.1
1.0.0-150002.3.3.1
0.1.1728559936.c16d4fb-150000.1.56.1
0.1.1710765237.46af599-150000.1.53.2
0.1.1710765237.46af599-159000.3.33.2
0.1.1681904360.84ef141-159000.3.30.1
0.1.1681904360.84ef141-150000.1.50.1
0.1.1674034019.a93ff61-150000.1.47.1
0.1.1673279145.e7616bd-150000.1.44.1
0.1.1661440542.6cbe0da-150000.1.38.1
0.1.1657643023.0d694ce-150000.1.35.1
Vulnerabilities (83)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU104016 - Exposure of sensitive information to an unauthorized actor CVE-2024-22037 |
CWE-200 | Low | 0.1.1728559936.c16d4fb-150000.1.56.1 | 17.02.2025 |
SB2025021737 SB2025021738 SB2025021739 and 5 more |
||
| #VU101894 - Insufficient Technical Documentation CVE-2024-51744 |
CWE-1059 | Low | 0.1.1728559936.c16d4fb-150000.1.56.1 | 23.12.2024 |
SB2024122304 SB2024122309 SB20241230139 and 21 more |
||
| #VU99259 - Improper Access Control CVE-2024-8118 |
CWE-284 | Low | 0.1.1728559936.c16d4fb-150000.1.56.1 | 22.10.2024 |
SB20241022375 SB2025021467 SB2025021742 and 1 more |
||
| #VU96048 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-6837 |
CWE-79 | Medium | 0.1.1728559936.c16d4fb-150000.1.56.1 | 15.08.2024 |
SB2024081534 SB2025021467 SB2025021742 and 1 more |
||
| #VU89210 - Incorrect Authorization CVE-2023-6152 |
CWE-863 | Low | 0.1.1710765237.46af599-150000.1.53.2, 0.1.1710765237.46af599-159000.3.33.2, 0.1.1728559936.c16d4fb-150000.1.56.1 | 07.05.2024 |
SB2024050715 SB2024050717 SB2024050718 and 8 more |
||
| #VU87845 - Improper Authorization CVE-2024-1313 |
CWE-285 | Medium | 0.1.1710765237.46af599-150000.1.53.2 | 27.03.2024 |
SB2024032711 SB2024043089 SB2024050720 and 10 more |
||
| #VU85621 - Missing release of memory after effective lifetime CVE-2024-0690 |
CWE-401 | Low | 0.1.1710765237.46af599-150000.1.53.2, 0.1.1710765237.46af599-159000.3.33.2 | 19.01.2024 |
SB2024011931 SB2024011933 SB2024011934 and 11 more |
||
| #VU84381 - Improper Control of Generation of Code ('Code Injection') CVE-2023-5764 |
CWE-94 | Medium | 0.1.1710765237.46af599-150000.1.53.2, 0.1.1710765237.46af599-159000.3.33.2 | 13.12.2023 |
SB2023121315 SB2023121316 SB2023121317 and 16 more |
||
| #VU77652 - Improper Authentication CVE-2023-3128 |
CWE-287 | High | 0.1.1681904360.84ef141-159000.3.30.1, 0.1.1728559936.c16d4fb-150000.1.56.1 | 22.06.2023 |
SB2023062281 SB2023071336 SB20230720114 and 15 more |
||
| #VU47274 - Improper Verification of Cryptographic Signature CVE-2020-14365 |
CWE-347 | Low | 0.1.1710765237.46af599-150000.1.53.2, 0.1.1710765237.46af599-159000.3.33.2 | 23.09.2020 |
SB2020092344 SB2020100222 SB2020102019 and 12 more |
||
| #VU47114 - Improper input validation CVE-2020-14330 |
CWE-20 | Low | 0.1.1710765237.46af599-150000.1.53.2 | 11.09.2020 |
SB2020092608 SB2020102017 SB2021080804 and 8 more |
||
| #VU47115 - Information Exposure Through Log Files CVE-2020-14332 |
CWE-532 | Low | 0.1.1710765237.46af599-150000.1.53.2 | 11.09.2020 |
SB2020092609 SB2020102018 SB2021080804 and 7 more |
||
| #VU29567 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2020-10744 |
CWE-362 | Low | 0.1.1710765237.46af599-150000.1.53.2 | 07.07.2020 |
SB2020051522 SB2024050721 |
||
| #VU29029 - Information Exposure Through Log Files CVE-2020-1753 |
CWE-532 | Low | 0.1.1710765237.46af599-150000.1.53.2 | 15.06.2020 |
SB2020032420 SB2020061518 SB2021080804 and 11 more |
||
| #VU36806 - Key Management Errors CVE-2016-8614 |
CWE-320 | Medium | 0.1.1710765237.46af599-150000.1.53.2 | 31.07.2018 |
SB2018073121 SB2024050721 SB2016110217 and 7 more |
||
| #VU36808 - Command injection CVE-2016-8628 |
CWE-77 | High | 0.1.1710765237.46af599-150000.1.53.2 | 31.07.2018 |
SB2018073121 SB2024050721 SB2016110217 and 8 more |
||
| #VU14157 - Permissions, Privileges, and Access Controls CVE-2018-10874 |
CWE-264 | Low | 0.1.1710765237.46af599-150000.1.53.2, 0.1.1710765237.46af599-159000.3.33.2 | 31.07.2018 |
SB2018080113 SB2018073118 SB2019011610 and 10 more |
||
| #VU12555 - Information Exposure Through Log Files CVE-2017-7550 |
CWE-532 | Low | 0.1.1710765237.46af599-150000.1.53.2, 0.1.1710765237.46af599-159000.3.33.2 | 05.03.2018 |
SB2018030511 SB2017101940 SB2024050718 and 4 more |
||
| #VU7411 - Improper input validation CVE-2016-8647 |
CWE-20 | Low | 0.1.1710765237.46af599-150000.1.53.2, 0.1.1710765237.46af599-159000.3.33.2 | 11.07.2017 |
SB2017070615 SB2024050718 SB2024050721 and 4 more |
||
| #VU6639 - Improper input validation CVE-2017-7466 |
CWE-20 | Medium | 0.1.1710765237.46af599-150000.1.53.2, 0.1.1710765237.46af599-159000.3.33.2 | 17.05.2017 |
SB2017052310 SB2017052601 SB2017070615 and 22 more |
Showing elements 21 - 40 out of 83