Known vulnerabilities in dracut-saltboot - page 3
Vendor:
SUSE
Software:
dracut-saltboot
Software CPE:
cpe:2.3:o:suse:dracut-saltboot:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
83
Public exploits:
6
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.4
Breakdown by Severity Chart
1.2.1-150002.3.9.1
1.1.0-159000.2.2.1
1.1.0-150000.1.65.1
1.1.0-150002.3.6.1
1.0.0-150002.3.3.1
0.1.1728559936.c16d4fb-150000.1.56.1
0.1.1710765237.46af599-150000.1.53.2
0.1.1710765237.46af599-159000.3.33.2
0.1.1681904360.84ef141-159000.3.30.1
0.1.1681904360.84ef141-150000.1.50.1
0.1.1674034019.a93ff61-150000.1.47.1
0.1.1673279145.e7616bd-150000.1.44.1
0.1.1661440542.6cbe0da-150000.1.38.1
0.1.1657643023.0d694ce-150000.1.35.1
Vulnerabilities (83)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU78470 - Missing Authorization CVE-2023-2183 |
CWE-862 | Low | 0.1.1681904360.84ef141-159000.3.30.1 | 20.07.2023 |
SB20230720110 SB20230720114 SB20230720115 and 9 more |
||
| #VU77623 - Improper Synchronization CVE-2023-2801 |
CWE-662 | Medium | 0.1.1681904360.84ef141-159000.3.30.1 | 22.06.2023 |
SB2023062244 SB20230720114 SB20230720115 and 8 more |
||
| #VU77620 - Exposure of sensitive information to an unauthorized actor CVE-2023-1387 |
CWE-200 | Medium | 0.1.1681904360.84ef141-150000.1.50.1, 0.1.1681904360.84ef141-159000.3.30.1 | 22.06.2023 |
SB2023062227 SB2023062230 SB2023062231 and 7 more |
||
| #VU75360 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-1410 |
CWE-79 | Low | 0.1.1681904360.84ef141-150000.1.50.1, 0.1.1681904360.84ef141-159000.3.30.1 | 19.04.2023 |
SB2023041950 SB2023041951 SB2023041952 and 11 more |
||
| #VU75359 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-0594 |
CWE-79 | Low | 0.1.1681904360.84ef141-159000.3.30.1 | 19.04.2023 |
SB2023041949 SB2023041951 SB2023041952 and 6 more |
||
| #VU75358 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-0507 |
CWE-79 | Low | 0.1.1681904360.84ef141-159000.3.30.1 | 19.04.2023 |
SB2023041949 SB2023041951 SB2023041952 and 6 more |
||
| #VU72686 - Resource exhaustion CVE-2022-41723 |
CWE-400 | Medium | 0.1.1674034019.a93ff61-150000.1.47.1, 0.1.1681904360.84ef141-159000.3.30.1 | 01.03.2023 |
SB2023030130 SB2023030131 SB2023030946 and 190 more |
||
| #VU72132 - Improper Authentication CVE-2022-39229 |
CWE-287 | Low | 0.1.1673279145.e7616bd-150000.1.44.1, 0.1.1681904360.84ef141-159000.3.30.1 | 12.02.2023 |
SB2023021201 SB2023021202 SB2023021203 and 13 more |
||
| #VU72131 - Exposure of sensitive information to an unauthorized actor CVE-2022-39201 |
CWE-200 | Medium | 0.1.1673279145.e7616bd-150000.1.44.1, 0.1.1681904360.84ef141-159000.3.30.1 | 12.02.2023 |
SB2023021201 SB2023021202 SB2023021203 and 12 more |
||
| #VU72130 - Exposure of sensitive information to an unauthorized actor CVE-2022-31130 |
CWE-200 | Medium | 0.1.1673279145.e7616bd-150000.1.44.1, 0.1.1681904360.84ef141-159000.3.30.1 | 12.02.2023 |
SB2023021201 SB2023021202 SB2023021203 and 11 more |
||
| #VU72128 - Improper Verification of Cryptographic Signature CVE-2022-31123 |
CWE-347 | Medium | 0.1.1673279145.e7616bd-150000.1.44.1, 0.1.1681904360.84ef141-159000.3.30.1 | 11.02.2023 |
SB2023021201 SB2023021202 SB2023021203 and 15 more |
||
| #VU71566 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing) CVE-2022-39324 |
CWE-451 | Low | 0.1.1674034019.a93ff61-150000.1.47.1, 0.1.1681904360.84ef141-159000.3.30.1 | 26.01.2023 |
SB2023012631 SB2023032032 SB2023032033 and 12 more |
||
| #VU69691 - Use of Password Hash Instead of Password for Authentication CVE-2022-46146 |
CWE-836 | Low | 0.1.1674034019.a93ff61-150000.1.47.1, 0.1.1681904360.84ef141-150000.1.50.1, 0.1.1681904360.84ef141-159000.3.30.1 | 29.11.2022 |
SB2022112926 SB2022113012 SB2023022044 and 33 more |
||
| #VU69485 - Exposure of sensitive information to an unauthorized actor CVE-2022-39307 |
CWE-200 | Medium | 0.1.1673279145.e7616bd-150000.1.44.1, 0.1.1681904360.84ef141-159000.3.30.1 | 22.11.2022 |
SB2022112220 SB2023021202 SB2023021203 and 12 more |
||
| #VU69484 - Improper input validation CVE-2022-39306 |
CWE-20 | Medium | 0.1.1673279145.e7616bd-150000.1.44.1, 0.1.1681904360.84ef141-159000.3.30.1 | 22.11.2022 |
SB2022112220 SB2023021202 SB2023021203 and 12 more |
||
| #VU68897 - Resource exhaustion CVE-2022-32149 |
CWE-400 | Medium | 0.1.1681904360.84ef141-150000.1.50.1, 0.1.1681904360.84ef141-159000.3.30.1 | 01.11.2022 |
SB2022110139 SB2022110140 SB2022110142 and 68 more |
||
| #VU68557 - Authentication Bypass Using an Alternate Path or Channel CVE-2022-35957 |
CWE-288 | Low | 0.1.1681904360.84ef141-150000.1.50.1, 0.1.1681904360.84ef141-159000.3.30.1 | 20.10.2022 |
SB2022092614 SB2022102094 SB2023050969 and 16 more |
||
| #VU68390 - Resource exhaustion CVE-2022-41715 |
CWE-400 | Medium | 0.1.1681904360.84ef141-150000.1.50.1, 0.1.1681904360.84ef141-159000.3.30.1 | 18.10.2022 |
SB2022101833 SB2022101834 SB2022102005 and 113 more |
||
| #VU67646 - Permissions, Privileges, and Access Controls CVE-2022-36062 |
CWE-264 | Medium | 0.1.1681904360.84ef141-150000.1.50.1, 0.1.1681904360.84ef141-159000.3.30.1 | 26.09.2022 |
SB2022092614 SB2022102094 SB2023062230 and 10 more |
||
| #VU65354 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2022-31097 |
CWE-79 | Low | 0.1.1661440542.6cbe0da-150000.1.38.1, 0.1.1681904360.84ef141-150000.1.50.1, 0.1.1681904360.84ef141-159000.3.30.1 | 15.07.2022 |
SB2022071510 SB2022102094 SB2022102641 and 16 more |
Showing elements 41 - 60 out of 83