Known vulnerabilities in netty - page 4
Vendor:
SUSE
Software:
netty
Software CPE:
cpe:2.3:o:suse:netty:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
70
Public exploits:
3
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
4.1.136-150200.4.53.1
4.1.135-150200.4.50.1
4.1.133-150200.4.46.1
4.1.132-150200.4.43.1
4.1.130-150200.4.40.1
4.1.128-150200.4.37.1
4.1.126-150200.4.34.1
4.1.44.Final-150400.3.9.1
4.1.44.Final-150400.3.6.3
4.1.118-150200.4.29.2
4.1.115-150200.4.26.1
4.1.108-150200.4.23.1
4.1.100-150200.4.20.1
4.1.94-150200.4.17.1
4.1.90-150200.4.14.1
4.1.75-150200.4.9.1
4.1.44.Final-150200.3.4.2
4.1.44.Final-150400.3.3.2
4.1.44.Final-150300.4.3.2
Vulnerabilities (70)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU81728 - Resource exhaustion CVE-2023-44487 |
CWE-400 | High | 4.1.100-150200.4.20.1 | 10.10.2023 |
SB2023101023 SB2023101024 SB2023101037 and 650 more |
||
| #VU77573 - Resource exhaustion CVE-2023-34462 |
CWE-400 | Medium | 4.1.94-150200.4.17.1 | 20.06.2023 |
SB2023062026 SB2023072521 SB2023072539 and 98 more |
||
| #VU70119 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2022-41915 |
CWE-113 | Medium | 4.1.90-150200.4.14.1 | 12.12.2022 |
SB2022121215 SB2023011210 SB2023013027 and 25 more |
||
| #VU70118 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2022-41881 |
CWE-835 | Medium | 4.1.90-150200.4.14.1 | 12.12.2022 |
SB2022121215 SB2023011210 SB2023011757 and 74 more |
||
| #VU63127 - Resource exhaustion CVE-2021-37136 |
CWE-400 | Medium | 4.1.44.Final-150200.3.4.2, 4.1.44.Final-150300.4.3.2, 4.1.44.Final-150400.3.3.2 | 12.05.2022 |
SB2021101948 SB2022051235 SB2022060838 and 36 more |
||
| #VU62849 - Creation of Temporary File With Insecure Permissions CVE-2022-24823 |
CWE-378 | Low | 4.1.90-150200.4.14.1 | 09.05.2022 |
SB2022050902 SB2022063002 SB2022072013 and 55 more |
||
| #VU59924 - Improper input validation CVE-2021-37137 |
CWE-20 | Medium | 4.1.44.Final-150200.3.4.2, 4.1.44.Final-150300.4.3.2, 4.1.44.Final-150400.3.3.2 | 23.01.2022 |
SB2022012310 SB2022012745 SB2022012753 and 43 more |
||
| #VU51837 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2021-21409 |
CWE-444 | Medium | 4.1.75-150200.4.9.1 | 01.04.2021 |
SB2021040116 SB2021040626 SB2021050706 and 32 more |
||
| #VU51835 - Cleartext Storage of Sensitive Information CVE-2021-21290 |
CWE-312 | Low | 4.1.44.Final-150200.3.4.2, 4.1.44.Final-150300.4.3.2, 4.1.44.Final-150400.3.3.2 | 01.04.2021 |
SB2021020813 SB2021040626 SB2021050706 and 42 more |
||
| #VU27513 - Resource exhaustion CVE-2020-11612 |
CWE-400 | Medium | 4.1.44.Final-150200.3.4.2, 4.1.44.Final-150300.4.3.2, 4.1.44.Final-150400.3.3.2 | 04.05.2020 |
SB2020050435 SB2020073033 SB2021012210 and 35 more |
Showing elements 61 - 80 out of 70