Direct Vulnerabilities

Known vulnerabilities in the firefox package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Cross-site Scripting (XSS)

*
  • L
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • H
Expired Pointer Dereference

*
  • H
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • H
Access of Uninitialized Pointer

*
  • H
Access of Uninitialized Pointer

*
  • H
Access of Uninitialized Pointer

*
  • H
Incorrect Privilege Assignment

*
  • H
Out-of-bounds Write

*
  • M
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Out-of-bounds Write

*
  • M
Use of Potentially Dangerous Function

*
  • H
Out-of-bounds Write

*
  • M
Use of Out-of-range Pointer Offset

*
  • H
Expired Pointer Dereference

*
  • H
Incorrect Calculation of Buffer Size

*
  • L
Incorrect Calculation of Buffer Size

*
  • M
Improper Handling of File Names

*
  • M
Out-of-bounds Read

*
  • H
Out-of-bounds Write

*
  • M
Incorrect Privilege Assignment

*
  • M
Exposure of Private Information ('Privacy Violation')

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Incorrect Privilege Assignment

*
  • M
Expected Behavior Violation

*
  • M
Improperly Implemented Security Check for Standard

*
  • M
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • H
Expired Pointer Dereference

<0:140.9.0-1.el7_9
  • H
Buffer Overflow

<0:140.9.0-1.el7_9
  • H
Buffer Access with Incorrect Length Value

<0:140.9.0-1.el7_9
  • H
Undefined Behavior for Input to API

<0:140.9.0-1.el7_9
  • H
Incorrect Privilege Assignment

<0:140.9.0-1.el7_9
  • H
Access of Uninitialized Pointer

<0:140.9.0-1.el7_9
  • H
Access of Uninitialized Pointer

<0:140.9.0-1.el7_9
  • H
Out-of-bounds Read

<0:140.9.0-1.el7_9
  • H
Out-of-bounds Write

<0:140.9.0-1.el7_9
  • H
Exposure of Private Information ('Privacy Violation')

<0:140.9.0-1.el7_9
  • H
Expired Pointer Dereference

<0:140.9.0-1.el7_9
  • H
Out-of-bounds Write

<0:140.9.0-1.el7_9
  • H
Out-of-bounds Write

<0:140.9.0-1.el7_9
  • H
Out-of-bounds Write

<0:140.9.0-1.el7_9
  • H
Use of Out-of-range Pointer Offset

<0:140.9.0-1.el7_9
  • H
Out-of-bounds Write

<0:140.9.0-1.el7_9
  • H
Undefined Behavior for Input to API

<0:140.9.0-1.el7_9
  • H
Allocation of Resources Without Limits or Throttling

<0:140.9.0-1.el7_9
  • H
Compiler Optimization Removal or Modification of Security-critical Code

<0:140.9.0-1.el7_9
  • H
Expired Pointer Dereference

<0:140.9.0-1.el7_9
  • H
HTTP Request Smuggling

<0:140.9.0-1.el7_9
  • H
Out-of-bounds Write

<0:140.9.0-1.el7_9
  • H
Compiler Optimization Removal or Modification of Security-critical Code

<0:140.9.0-1.el7_9
  • H
Out-of-bounds Write

<0:140.9.0-1.el7_9
  • H
Expired Pointer Dereference

<0:140.9.0-1.el7_9
  • H
Incorrect Calculation of Buffer Size

<0:140.9.0-1.el7_9
  • H
Integer Overflow or Wraparound

<0:140.9.0-1.el7_9
  • H
Use of Out-of-range Pointer Offset

<0:140.9.0-1.el7_9
  • H
Insufficient Compartmentalization

<0:140.9.0-1.el7_9
  • H
Expired Pointer Dereference

<0:140.9.0-1.el7_9
  • H
Integer Overflow or Wraparound

<0:140.9.0-1.el7_9
  • H
Integer Overflow or Wraparound

<0:140.9.0-1.el7_9
  • H
Expired Pointer Dereference

<0:140.9.0-1.el7_9
  • H
Trust Boundary Violation

<0:140.9.0-1.el7_9
  • H
Out-of-bounds Write

<0:140.9.0-1.el7_9
  • H
Out-of-bounds Write

<0:140.9.0-1.el7_9
  • H
Race Condition

<0:140.9.0-1.el7_9
  • M
Integer Overflow or Wraparound

*
  • M
Expired Pointer Dereference

*
  • H
Out-of-bounds Write

*
  • H
Integer Overflow or Wraparound

*
  • M
NULL Pointer Dereference

*
  • H
Out-of-bounds Write

*
  • H
Arbitrary Code Injection

*
  • H
Expression Language Injection

*
  • H
Arbitrary Code Injection

*
  • M
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • H
Uncaught Exception

*
  • H
Arbitrary Code Injection

*
  • H
Arbitrary Code Injection

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Buffer Underflow

*
  • M
Expired Pointer Dereference

*
  • M
Access of Uninitialized Pointer

*
  • H
Expired Pointer Dereference

*
  • H
Out-of-bounds Write

*
  • H
Expired Pointer Dereference

*
  • M
Access of Uninitialized Pointer

*
  • M
Exposure of Private Information ('Privacy Violation')

*
  • H
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • H
Incorrect Calculation of Buffer Size

*
  • H
Integer Overflow or Wraparound

*
  • H
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Write

*
  • H
Use of Out-of-range Pointer Offset

*
  • M
Undefined Behavior for Input to API

*
  • L
Buffer Access with Incorrect Length Value

*
  • M
Expired Pointer Dereference

*
  • H
Buffer Overflow

*
  • H
Expired Pointer Dereference

*
  • H
Insufficient Compartmentalization

*
  • L
Undefined Behavior for Input to API

*
  • H
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • H
Compiler Optimization Removal or Modification of Security-critical Code

*
  • M
Incorrect Privilege Assignment

*
  • M
Use of Out-of-range Pointer Offset

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • H
Expired Pointer Dereference

*
  • H
Out-of-bounds Write

*
  • H
HTTP Request Smuggling

*
  • M
Compiler Optimization Removal or Modification of Security-critical Code

*
  • H
Trust Boundary Violation

*
  • H
Out-of-bounds Write

*
  • H
Race Condition

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Unchecked Input for Loop Condition

*
  • H
CVE-2026-2769

*
  • H
Use After Free

*
  • M
CVE-2026-2788

*
  • H
Uncaught Exception

*
  • H
Out-of-bounds Write

*
  • H
CVE-2026-2775

*
  • H
Out-of-bounds Read

*
  • H
CVE-2026-2773

*
  • H
Integer Overflow or Wraparound

*
  • H
CVE-2026-2447

*
  • L
CVE-2026-2791

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
CVE-2026-2779

*
  • H
Out-of-bounds Write

*
  • M
CVE-2026-23865

*
  • H
Use After Free

*
  • M
Incorrect Behavior Order: Early Validation

*
  • H
Use After Free

*
  • H
Use After Free

*
  • L
Out-of-bounds Read

*
  • H
CVE-2026-0891

<0:140.7.0-1.el7_9
  • H
CVE-2026-0890

<0:140.7.0-1.el7_9
  • H
CVE-2026-0887

<0:140.7.0-1.el7_9
  • H
CVE-2026-0886

<0:140.7.0-1.el7_9
  • H
CVE-2026-0885

<0:140.7.0-1.el7_9
  • H
CVE-2026-0884

<0:140.7.0-1.el7_9
  • H
CVE-2026-0883

<0:140.7.0-1.el7_9
  • H
CVE-2026-0882

<0:140.7.0-1.el7_9
  • H
CVE-2026-0880

<0:140.7.0-1.el7_9
  • H
CVE-2026-0879

<0:140.7.0-1.el7_9
  • H
CVE-2026-0878

<0:140.7.0-1.el7_9
  • H
CVE-2026-0877

<0:140.7.0-1.el7_9
  • H
Authentication Bypass

<0:140.7.0-1.el7_9
  • H
Out-of-bounds Write

<0:140.8.0-2.el7_9
  • H
Out-of-bounds Write

<0:140.8.0-2.el7_9
  • H
CVE-2026-2791

<0:140.8.0-2.el7_9
  • H
CVE-2026-2790

<0:140.8.0-2.el7_9
  • H
Use After Free

<0:140.8.0-2.el7_9
  • H
CVE-2026-2788

<0:140.8.0-2.el7_9
  • H
Use After Free

<0:140.8.0-2.el7_9
  • H
Use After Free

<0:140.8.0-2.el7_9
  • H
Access of Uninitialized Pointer

<0:140.8.0-2.el7_9
  • H
CVE-2026-2784

<0:140.8.0-2.el7_9
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<0:140.8.0-2.el7_9
  • H
CVE-2026-2782

<0:140.8.0-2.el7_9
  • H
Integer Overflow or Wraparound

<0:140.8.0-2.el7_9
  • H
CVE-2026-2780

<0:140.8.0-2.el7_9
  • H
CVE-2026-2779

<0:140.8.0-2.el7_9
  • H
CVE-2026-2778

<0:140.8.0-2.el7_9
  • H
CVE-2026-2777

<0:140.8.0-2.el7_9
  • H
CVE-2026-2776

<0:140.8.0-2.el7_9
  • H
CVE-2026-2775

<0:140.8.0-2.el7_9
  • H
Integer Overflow or Wraparound

<0:140.8.0-2.el7_9
  • H
CVE-2026-2773

<0:140.8.0-2.el7_9
  • H
Use After Free

<0:140.8.0-2.el7_9
  • H
CVE-2026-2771

<0:140.8.0-2.el7_9
  • H
Use After Free

<0:140.8.0-2.el7_9
  • H
CVE-2026-2769

<0:140.8.0-2.el7_9
  • H
CVE-2026-2768

<0:140.8.0-2.el7_9
  • H
Use After Free

<0:140.8.0-2.el7_9
  • H
Use After Free

<0:140.8.0-2.el7_9
  • H
Use After Free

<0:140.8.0-2.el7_9
  • H
Use After Free

<0:140.8.0-2.el7_9
  • H
Use After Free

<0:140.8.0-2.el7_9
  • H
Integer Overflow or Wraparound

<0:140.8.0-2.el7_9
  • H
CVE-2026-2761

<0:140.8.0-2.el7_9
  • H
CVE-2026-2760

<0:140.8.0-2.el7_9
  • H
CVE-2026-2759

<0:140.8.0-2.el7_9
  • H
Use After Free

<0:140.8.0-2.el7_9
  • H
CVE-2026-2757

<0:140.8.0-2.el7_9
  • H
CVE-2026-2447

<0:140.8.0-2.el7_9
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Buffer Overflow

*
  • M
CRLF Injection

*
  • M
Deserialization of Untrusted Data

*
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • M
Improper Input Validation

*
  • M
CRLF Injection

*
  • M
Arbitrary Code Injection

*
  • M
CRLF Injection

*
  • M
Arbitrary Command Injection

*
  • M
Arbitrary Command Injection

*
  • M
Improper Neutralization

*
  • L
CVE-2026-0890

*
  • M
CVE-2026-0887

*
  • M
NULL Pointer Dereference

*
  • M
CVE-2026-0883

*
  • M
CVE-2026-0884

*
  • H
CVE-2026-0882

*
  • H
CVE-2026-0880

*
  • M
CVE-2026-0886

*
  • H
CVE-2026-0877

*
  • H
CVE-2026-0891

*
  • M
CVE-2026-0885

*
  • H
CVE-2026-0879

*
  • H
CVE-2026-0878

*
  • M
Authentication Bypass

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • H
Out-of-bounds Write

<0:140.6.0-1.el7_9
  • H
Origin Validation Error

<0:140.6.0-1.el7_9
  • H
CVE-2025-14330

<0:140.6.0-1.el7_9
  • H
CVE-2025-14329

<0:140.6.0-1.el7_9
  • H
CVE-2025-14328

<0:140.6.0-1.el7_9
  • H
Arbitrary Code Injection

<0:140.6.0-1.el7_9
  • H
CVE-2025-14324

<0:140.6.0-1.el7_9
  • H
CVE-2025-14323

<0:140.6.0-1.el7_9
  • H
CVE-2025-14322

<0:140.6.0-1.el7_9
  • H
Use After Free

<0:140.6.0-1.el7_9
  • M
CVE-2025-14330

*
  • M
Origin Validation Error

*
  • M
CVE-2025-14328

*
  • H
CVE-2025-14322

*
  • H
Arbitrary Code Injection

*
  • H
CVE-2025-14323

*
  • M
Out-of-bounds Write

*
  • H
CVE-2025-14324

*
  • M
CVE-2025-14329

*
  • M
Improper Verification of Source of a Communication Channel

*
  • H
Cross-site Scripting (XSS)

*
  • M
Out-of-bounds Read

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Expired Pointer Dereference

<0:140.5.0-1.el7_9
  • H
Origin Validation Error

<0:140.5.0-1.el7_9
  • H
Cross-site Scripting (XSS)

<0:140.5.0-1.el7_9
  • H
Trust Boundary Violation

<0:140.5.0-1.el7_9
  • H
Out-of-bounds Write

<0:140.5.0-1.el7_9
  • H
Authentication Bypass

<0:140.5.0-1.el7_9
  • H
Expired Pointer Dereference

<0:140.5.0-1.el7_9
  • H
Cross-site Scripting (XSS)

<0:140.5.0-1.el7_9
  • H
Race Condition

<0:140.5.0-1.el7_9
  • L
Algorithmic Complexity

*
  • M
Out-of-bounds Read

*
  • H
CVE-2025-11152

*
  • M
Cross-site Scripting (XSS)

*
  • H
Race Condition

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • L
Authentication Bypass

*
  • H
Out-of-bounds Write

*
  • M
Trust Boundary Violation

*
  • M
Origin Validation Error

*
  • M
Cross-site Scripting (XSS)

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • H
Out-of-Bounds

<0:140.4.0-4.el7_9
  • H
Out-of-Bounds

<0:140.4.0-4.el7_9
  • H
Interpretation Conflict

<0:140.4.0-4.el7_9
  • H
Improper Access Control

<0:140.4.0-4.el7_9
  • H
Exposure of System Data to an Unauthorized Control Sphere

<0:140.4.0-4.el7_9
  • H
Out-of-bounds Write

<0:140.4.0-4.el7_9
  • H
Use After Free

<0:140.4.0-4.el7_9
  • M
Interpretation Conflict

*
  • H
Use After Free

*
  • H
Out-of-Bounds

*
  • H
Out-of-bounds Write

*
  • H
Out-of-Bounds

*
  • H
Exposure of System Data to an Unauthorized Control Sphere

*
  • H
Improper Access Control

*
  • H
CVE-2025-10537

<0:140.3.0-1.el7_9
  • H
CVE-2025-10536

<0:140.3.0-1.el7_9
  • H
Integer Overflow or Wraparound

<0:140.3.0-1.el7_9
  • H
Out-of-bounds Read

<0:140.3.0-1.el7_9
  • H
CVE-2025-10529

<0:140.3.0-1.el7_9
  • H
Access of Uninitialized Pointer

<0:140.3.0-1.el7_9
  • H
Use After Free

<0:140.3.0-1.el7_9
  • M
Integer Overflow or Wraparound

*
  • H
Access of Uninitialized Pointer

*
  • H
CVE-2025-10537

*
  • H
Use After Free

*
  • L
CVE-2025-10536

*
  • M
CVE-2025-10529

*
  • M
Out-of-bounds Read

*
  • H
Out-of-Bounds

<0:128.14.0-2.el7_9
  • H
Resource Exhaustion

<0:128.14.0-2.el7_9
  • H
Improper Initialization

<0:128.14.0-2.el7_9
  • H
Information Exposure

<0:128.14.0-2.el7_9
  • H
Out-of-Bounds

<0:128.14.0-2.el7_9
  • M
Information Exposure Through Caching

*
  • L
Improper Neutralization

*
  • M
Improper Input Validation

*
  • M
Improper Initialization

*
  • H
Out-of-Bounds

*
  • H
Information Exposure

*
  • H
Improper Input Validation

*
  • H
Out-of-Bounds

*
  • M
Integer Overflow or Wraparound

*
  • H
Out-of-Bounds

<0:128.13.0-1.el7_9
  • H
Out-of-Bounds

<0:128.13.0-1.el7_9
  • H
NULL Pointer Dereference

<0:128.13.0-1.el7_9
  • H
Protection Mechanism Failure

<0:128.13.0-1.el7_9
  • H
Incorrect Default Permissions

<0:128.13.0-1.el7_9
  • H
Arbitrary Code Injection

<0:128.13.0-1.el7_9
  • H
Cross-site Scripting (XSS)

<0:128.13.0-1.el7_9
  • H
Insufficient Protection Against Instruction Skipping Via Fault Injection

<0:128.13.0-1.el7_9
  • H
Use of Uninitialized Variable

<0:128.13.0-1.el7_9
  • M
Buffer Over-read

*
  • L
Improper Encoding or Escaping of Output

*
  • H
Out-of-Bounds

*
  • L
NULL Pointer Dereference

*
  • M
Protection Mechanism Failure

*
  • H
Insufficient Protection Against Instruction Skipping Via Fault Injection

*
  • H
Use of Uninitialized Variable

*
  • M
Incorrect Default Permissions

*
  • M
Cross-site Scripting (XSS)

*
  • M
Arbitrary Code Injection

*
  • H
Out-of-Bounds

*
  • M
Use of Insufficiently Random Values

*
  • H
Numeric Truncation Error

*
  • L
HTTP Request Smuggling

*
  • M
HTTP Request Smuggling

*
  • H
Cross-site Scripting (XSS)

<0:128.12.0-1.el7_9
  • H
Use of Incorrectly-Resolved Name or Reference

<0:128.12.0-1.el7_9
  • H
Information Exposure

<0:128.12.0-1.el7_9
  • H
Use After Free

<0:128.12.0-1.el7_9
  • L
Improper Input Validation

*
  • L
Out-of-Bounds

*
  • L
Resource Exhaustion

*
  • L
Reachable Assertion

*
  • C
Integer Overflow or Wraparound

<0:91.7.0-3.el7_9
  • C
Integer Overflow or Wraparound

<0:91.7.0-3.el7_9
  • C
Integer Overflow or Wraparound

<0:91.7.0-3.el7_9
  • L
Inefficient Regular Expression Complexity

*
  • H
Double Free

<0:128.11.0-1.el7_9
  • H
Out-of-Bounds

<0:128.11.0-1.el7_9
  • H
Out-of-Bounds

<0:128.11.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:128.11.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:128.11.0-1.el7_9
  • H
Improper Encoding or Escaping of Output

<0:128.11.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:128.11.0-1.el7_9
  • H
Out-of-bounds Write

<0:128.10.1-1.el7_9
  • H
Out-of-bounds Write

<0:128.10.1-1.el7_9
  • M
CVE-2025-48068

*
  • M
Improper Validation of Unsafe Equivalence in Input

*
  • L
Improper Restriction of Rendered UI Layers or Frames

*
  • M
Out-of-Bounds

*
  • M
Out-of-Bounds

*
  • M
Inclusion of Functionality from Untrusted Control Sphere

*
  • M
Inclusion of Functionality from Untrusted Control Sphere

*
  • M
Improper Encoding or Escaping of Output

*
  • H
Out-of-bounds Write

*
  • H
Out-of-bounds Write

*
  • M
Double Free

*
  • L
Race Condition

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Buffer Overflow

<0:128.10.0-1.el7_9
  • H
Buffer Overflow

<0:128.10.0-1.el7_9
  • H
Out-of-bounds Read

<0:128.10.0-1.el7_9
  • H
Insufficient Compartmentalization

<0:128.10.0-1.el7_9
  • H
Arbitrary Code Injection

<0:128.10.0-1.el7_9
  • H
Insufficient Compartmentalization

*
  • M
Out-of-bounds Read

*
  • M
Buffer Overflow

*
  • H
Arbitrary Code Injection

*
  • H
Buffer Overflow

*
  • M
Incomplete Filtering of Special Elements

*
  • L
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

*
  • L
Use After Free

*
  • H
Buffer Overflow

<0:128.9.0-2.el7_9
  • H
Origin Validation Error

<0:128.9.0-2.el7_9
  • H
Use After Free

<0:128.9.0-2.el7_9
  • L
Information Exposure

*
  • M
Exposure of System Data to an Unauthorized Control Sphere

*
  • M
Information Exposure

*
  • M
Origin Validation Error

*
  • M
Out-of-bounds Write

*
  • M
Uncontrolled Recursion

*
  • H
Buffer Overflow

<0:128.8.0-1.el7_9
  • H
Buffer Overflow

<0:128.8.0-1.el7_9
  • H
Improper Check for Unusual or Exceptional Conditions

<0:128.8.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:128.8.0-1.el7_9
  • H
Improper Cleanup on Thrown Exception

<0:128.8.0-1.el7_9
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<0:128.8.0-1.el7_9
  • H
Out-of-bounds Read

<0:128.8.0-1.el7_9
  • H
Use After Free

<0:128.8.0-1.el7_9
  • H
Use After Free

<0:128.8.0-1.el7_9
  • M
Access of Uninitialized Pointer

*
  • H
Buffer Overflow

*
  • M
Missing Authentication for Critical Function

*
  • H
Buffer Overflow

*
  • H
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Buffer Overflow

*
  • H
Buffer Overflow

*
  • M
User Interface (UI) Misrepresentation of Critical Information

*
  • H
Buffer Overflow

<0:128.7.0-1.el7_9
  • H
Buffer Overflow

<0:128.7.0-1.el7_9
  • H
Improper Validation of Specified Quantity in Input

<0:128.7.0-1.el7_9
  • H
Race Condition

<0:128.7.0-1.el7_9
  • H
Use After Free

<0:128.7.0-1.el7_9
  • H
Out-of-Bounds

<0:128.7.0-1.el7_9
  • H
Use After Free

<0:128.7.0-1.el7_9
  • H
Use After Free

<0:128.7.0-1.el7_9
  • H
Buffer Overflow

<0:128.5.1-1.el7_9
  • H
Product UI does not Warn User of Unsafe Actions

<0:128.5.1-1.el7_9
  • H
Improper Validation of Integrity Check Value

<0:128.5.1-1.el7_9
  • H
User Interface (UI) Misrepresentation of Critical Information

<0:128.5.1-1.el7_9
  • H
Cross-site Scripting (XSS)

<0:128.5.1-1.el7_9
  • H
User Interface (UI) Misrepresentation of Critical Information

<0:128.5.1-1.el7_9
  • H
Buffer Overflow

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Buffer Overflow

<0:128.6.0-1.el7_9
  • H
Buffer Overflow

<0:128.6.0-1.el7_9
  • H
Out-of-Bounds

<0:128.6.0-1.el7_9
  • H
Use After Free

<0:128.6.0-1.el7_9
  • H
Open Redirect

<0:128.6.0-1.el7_9
  • H
Use After Free

<0:128.6.0-1.el7_9
  • H
Unintended Proxy or Intermediary ('Confused Deputy')

<0:128.6.0-1.el7_9
  • L
Incorrect Bitwise Shift of Integer

*
  • L
NULL Pointer Dereference

*
  • L
Out-of-bounds Read

*
  • L
Missing Synchronization

*
  • L
User Interface (UI) Misrepresentation of Critical Information

*
  • L
Double Free

*
  • M
Cross-site Scripting (XSS)

*
  • L
Product UI does not Warn User of Unsafe Actions

*
  • M
User Interface (UI) Misrepresentation of Critical Information

*
  • M
Cross-site Scripting (XSS)

*
  • M
Improper Validation of Integrity Check Value

*
  • H
Buffer Overflow

*
  • M
Resource Exhaustion

*
  • M
Out-of-bounds Read

*
  • L
CVE-2024-10941

*
  • M
Buffer Overflow

<0:128.4.0-1.el7_9
  • M
Resource Exhaustion

<0:128.4.0-1.el7_9
  • M
Improper Input Validation

<0:128.4.0-1.el7_9
  • M
Improper Control of Interaction Frequency

<0:128.4.0-1.el7_9
  • M
Overly Permissive Cross-domain Whitelist

<0:128.4.0-1.el7_9
  • M
Improper Handling of Insufficient Permissions or Privileges

<0:128.4.0-1.el7_9
  • M
Cross-site Scripting (XSS)

<0:128.4.0-1.el7_9
  • M
Improper Verification of Source of a Communication Channel

<0:128.4.0-1.el7_9
  • M
Use After Free

<0:128.4.0-1.el7_9
  • M
Improper Handling of Insufficient Permissions or Privileges

<0:128.4.0-1.el7_9
  • H
Out-of-bounds Read

<0:102.3.0-6.el7_9
  • L
Inefficient Regular Expression Complexity

*
  • H
Use After Free

<0:128.3.1-2.el7_9
  • H
Buffer Overflow

<0:128.3.0-1.el7_9
  • H
Buffer Overflow

<0:128.3.0-1.el7_9
  • H
Buffer Overflow

<0:128.3.0-1.el7_9
  • H
Uncontrolled Memory Allocation

<0:128.3.0-1.el7_9
  • H
Improper Check for Unusual or Exceptional Conditions

<0:128.3.0-1.el7_9
  • H
Information Exposure

<0:128.3.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:128.3.0-1.el7_9
  • H
Out-of-Bounds

<0:128.3.0-1.el7_9
  • H
Arbitrary Code Injection

<0:128.3.0-1.el7_9
  • H
Arbitrary Code Injection

<0:128.3.0-1.el7_9
  • H
Origin Validation Error

<0:128.3.0-1.el7_9
  • H
CVE-2024-8900

<0:128.3.0-1.el7_9
  • H
Buffer Overflow

<0:128.2.0-1.el7_9
  • H
Improperly Implemented Security Check for Standard

<0:128.2.0-1.el7_9
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<0:128.2.0-1.el7_9
  • H
Out-of-bounds Write

<0:128.2.0-1.el7_9
  • H
Missing Authorization

<0:128.2.0-1.el7_9
  • H
Exposure of System Data to an Unauthorized Control Sphere

<0:128.2.0-1.el7_9
  • H
Incorrect Type Conversion or Cast

<0:128.2.0-1.el7_9
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<0:128.2.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:115.6.0-1.el7_9
  • H
Use of Uninitialized Resource

<0:115.6.0-1.el7_9
  • H
Buffer Overflow

<0:115.6.0-1.el7_9
  • H
Improper Input Validation

<0:115.6.0-1.el7_9
  • H
Use After Free

<0:115.6.0-1.el7_9
  • H
Heap-based Buffer Overflow

<0:115.6.0-1.el7_9
  • H
Improper Input Validation

<0:115.6.0-1.el7_9
  • H
Use After Free

<0:115.6.0-1.el7_9
  • H
Heap-based Buffer Overflow

<0:115.6.0-1.el7_9
  • H
Race Condition

<0:115.6.0-1.el7_9
  • H
Heap-based Buffer Overflow

<0:115.6.0-1.el7_9
  • H
Buffer Overflow

<0:102.13.0-2.el7_9
  • H
Compilation with Insufficient Warnings or Errors

<0:102.13.0-2.el7_9
  • H
Authentication Bypass

<0:102.13.0-2.el7_9
  • H
Use After Free

<0:102.13.0-2.el7_9
  • H
Use After Free

<0:102.13.0-2.el7_9
  • H
Buffer Overflow

<0:115.8.0-1.el7_9
  • H
Incorrect Conversion between Numeric Types

<0:115.8.0-1.el7_9
  • H
Arbitrary Code Injection

<0:115.8.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:115.8.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:115.8.0-1.el7_9
  • H
The UI Performs the Wrong Action

<0:115.8.0-1.el7_9
  • H
The UI Performs the Wrong Action

<0:115.8.0-1.el7_9
  • H
Out-of-bounds Read

<0:115.8.0-1.el7_9
  • H
Buffer Overflow

<0:102.11.0-2.el7_9
  • H
Use of Uninitialized Variable

<0:102.11.0-2.el7_9
  • H
Insufficient Verification of Data Authenticity

<0:102.11.0-2.el7_9
  • H
Resource Exhaustion

<0:102.11.0-2.el7_9
  • H
Improper Handling of Insufficient Permissions or Privileges

<0:102.11.0-2.el7_9
  • H
Out-of-bounds Read

<0:102.11.0-2.el7_9
  • H
User Interface (UI) Misrepresentation of Critical Information

<0:102.11.0-2.el7_9
  • H
Buffer Overflow

<0:102.15.0-1.el7_9
  • H
Buffer Overflow

<0:102.15.0-1.el7_9
  • H
Incorrect Behavior Order: Early Validation

<0:102.15.0-1.el7_9
  • H
Compilation with Insufficient Warnings or Errors

<0:102.15.0-1.el7_9
  • H
Information Exposure

<0:102.15.0-1.el7_9
  • H
Out-of-Bounds

<0:102.15.0-1.el7_9
  • H
Resource Exhaustion

<0:102.15.0-1.el7_9
  • H
Use After Free

<0:102.15.0-1.el7_9
  • H
Use After Free

<0:102.15.0-1.el7_9
  • H
Use After Free

<0:102.15.0-1.el7_9
  • H
Authentication Bypass

<0:102.15.0-1.el7_9
  • H
Authentication Bypass

<0:102.15.0-1.el7_9
  • H
Multiple Interpretations of UI Input

<0:115.4.0-1.el7_9
  • H
Buffer Overflow

<0:115.4.0-1.el7_9
  • H
Memory Leak

<0:115.4.0-1.el7_9
  • H
Open Redirect

<0:115.4.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:115.4.0-1.el7_9
  • H
Product UI does not Warn User of Unsafe Actions

<0:115.4.0-1.el7_9
  • H
Improper Handling of Exceptional Conditions

<0:115.4.0-1.el7_9
  • H
Use After Free

<0:115.12.0-1.el7_9
  • H
Buffer Overflow

<0:115.12.0-1.el7_9
  • H
Improper Validation of Specified Type of Input

<0:115.12.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:115.12.0-1.el7_9
  • H
Improper Access Control

<0:115.12.0-1.el7_9
  • H
Covert Timing Channel

<0:115.12.0-1.el7_9
  • H
Use After Free

<0:115.12.0-1.el7_9
  • H
Buffer Overflow

<0:115.5.0-1.el7_9
  • H
Directory Traversal

<0:115.5.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:115.5.0-1.el7_9
  • H
Use After Free

<0:115.5.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:115.5.0-1.el7_9
  • H
Use After Free

<0:115.5.0-1.el7_9
  • H
Out-of-bounds Read

<0:115.5.0-1.el7_9
  • H
Buffer Overflow

<0:115.13.0-3.el7_9
  • H
Out-of-Bounds

<0:115.13.0-3.el7_9
  • H
Improper Preservation of Permissions

<0:115.13.0-3.el7_9
  • H
Buffer Overflow

<0:91.13.0-1.el7_9
  • H
Buffer Overflow

<0:91.13.0-1.el7_9
  • H
Use After Free

<0:91.13.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.13.0-1.el7_9
  • H
Product UI does not Warn User of Unsafe Actions

<0:91.13.0-1.el7_9
  • H
Use After Free

<0:102.6.0-1.el7_9
  • H
Out-of-Bounds

<0:102.6.0-1.el7_9
  • H
Use After Free

<0:102.6.0-1.el7_9
  • H
Buffer Overflow

<0:102.6.0-1.el7_9
  • H
Truncation of Security-relevant Information

<0:102.6.0-1.el7_9
  • H
Information Exposure

<0:102.6.0-1.el7_9
  • H
Buffer Overflow

<0:102.14.0-1.el7_9
  • H
Buffer Overflow

<0:102.14.0-1.el7_9
  • H
Reliance on Cookies without Validation and Integrity Checking in a Security Decision

<0:102.14.0-1.el7_9
  • H
Buffer Overflow

<0:102.14.0-1.el7_9
  • H
Race Condition

<0:102.14.0-1.el7_9
  • H
Out-of-bounds Read

<0:102.14.0-1.el7_9
  • H
Improper Handling of Insufficient Permissions or Privileges

<0:102.14.0-1.el7_9
  • H
Improper Input Validation

<0:102.14.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:102.14.0-1.el7_9
  • H
Buffer Overflow

<0:102.3.0-6.el7_9
  • H
Use After Free

<0:102.3.0-6.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:102.3.0-6.el7_9
  • H
Reliance on Cookies without Validation and Integrity Checking in a Security Decision

<0:102.3.0-6.el7_9
  • H
Improper Handling of Inconsistent Structural Elements

<0:102.3.0-6.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:102.3.0-6.el7_9
  • H
Buffer Overflow

<0:102.8.0-2.el7_9
  • H
Buffer Overflow

<0:102.8.0-2.el7_9
  • H
Insufficient UI Warning of Dangerous Operations

<0:102.8.0-2.el7_9
  • H
Improper Handling of Alternate Encoding

<0:102.8.0-2.el7_9
  • H
Use After Free

<0:102.8.0-2.el7_9
  • H
Incorrect Type Conversion or Cast

<0:102.8.0-2.el7_9
  • H
Use After Free

<0:102.8.0-2.el7_9
  • H
Out-of-bounds Write

<0:102.8.0-2.el7_9
  • H
Incorrect Synchronization

<0:102.8.0-2.el7_9
  • H
Cross-site Scripting (XSS)

<0:102.8.0-2.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:102.8.0-2.el7_9
  • H
Heap-based Buffer Overflow

<0:102.15.1-1.el7_9
  • H
Out-of-Bounds

<0:115.3.1-1.el7_9
  • H
Buffer Overflow

<0:115.3.1-1.el7_9
  • H
Use After Free

<0:115.3.1-1.el7_9
  • H
Out-of-bounds Write

<0:115.3.1-1.el7_9
  • H
Use After Free

<0:115.3.1-1.el7_9
  • H
Buffer Overflow

<0:91.6.0-1.el7_9
  • H
Arbitrary Code Injection

<0:91.6.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:91.6.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:91.6.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:91.6.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.6.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.6.0-1.el7_9
  • H
Buffer Overflow

<0:102.12.0-1.el7_9
  • H
The UI Performs the Wrong Action

<0:102.12.0-1.el7_9
  • H
Buffer Overflow

<0:91.11.0-2.el7_9
  • H
Integer Overflow or Wraparound

<0:91.11.0-2.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.11.0-2.el7_9
  • H
Return of Wrong Status Code

<0:91.11.0-2.el7_9
  • H
Use After Free

<0:91.11.0-2.el7_9
  • H
Cross-site Scripting (XSS)

<0:91.11.0-2.el7_9
  • H
Cross-site Scripting (XSS)

<0:91.11.0-2.el7_9
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<0:91.11.0-2.el7_9
  • H
Buffer Overflow

<0:102.9.0-3.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:102.9.0-3.el7_9
  • H
Incorrect Type Conversion or Cast

<0:102.9.0-3.el7_9
  • H
Out-of-bounds Read

<0:102.9.0-3.el7_9
  • H
Buffer Overflow

<0:91.9.0-1.el7_9
  • H
Arbitrary Code Injection

<0:102.9.0-3.el7_9
  • H
Exposure of System Data to an Unauthorized Control Sphere

<0:91.9.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.9.0-1.el7_9
  • H
Reliance on Cookies without Validation and Integrity Checking

<0:91.9.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.9.0-1.el7_9
  • H
Improper Preservation of Permissions

<0:91.9.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.12.0-2.el7_9
  • H
Cross-site Scripting (XSS)

<0:91.12.0-2.el7_9
  • H
Buffer Overflow

<0:91.12.0-2.el7_9
  • H
Buffer Overflow

<0:102.4.0-1.el7_9
  • H
Resource Exhaustion

<0:102.4.0-1.el7_9
  • H
Buffer Overflow

<0:102.4.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:102.4.0-1.el7_9
  • H
Buffer Overflow

<0:102.7.0-1.el7_9
  • H
Incorrect Regular Expression

<0:102.7.0-1.el7_9
  • H
CVE-2023-23602

<0:102.7.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:102.7.0-1.el7_9
  • H
Arbitrary Command Injection

<0:102.7.0-1.el7_9
  • H
Multiple Interpretations of UI Input

<0:102.7.0-1.el7_9
  • H
Insufficient UI Warning of Dangerous Operations

<0:102.7.0-1.el7_9
  • H
Use of Unmaintained Third Party Components

<0:102.7.0-1.el7_9
  • H
Buffer Overflow

<0:91.8.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.8.0-1.el7_9
  • H
Out-of-bounds Read

<0:91.8.0-1.el7_9
  • H
Use After Free

<0:91.8.0-1.el7_9
  • H
Out-of-bounds Write

<0:91.8.0-1.el7_9
  • H
Resource Exhaustion

<0:91.8.0-1.el7_9
  • H
Buffer Overflow

<0:115.11.0-1.el7_9
  • H
Use After Free

<0:91.8.0-1.el7_9
  • H
Use After Free

<0:115.11.0-1.el7_9
  • H
Use After Free

<0:91.8.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:115.11.0-1.el7_9
  • H
User Interface (UI) Misrepresentation of Critical Information

<0:115.11.0-1.el7_9
  • H
Improper Cross-boundary Removal of Sensitive Data

<0:115.11.0-1.el7_9
  • H
Improper Check for Unusual or Exceptional Conditions

<0:115.11.0-1.el7_9
  • H
Out-of-bounds Write

<0:78.12.0-1.el7_9
  • H
Buffer Overflow

<0:78.12.0-1.el7_9
  • H
Use After Free

<0:78.12.0-1.el7_9
  • C
Buffer Overflow

<0:78.8.0-1.el7_9
  • C
Information Exposure

<0:78.8.0-1.el7_9
  • C
Information Exposure

<0:78.8.0-1.el7_9
  • C
Information Exposure

<0:78.8.0-1.el7_9
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

<0:91.9.1-1.el7_9
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

<0:91.9.1-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.4.0-1.el7_9
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0:91.4.0-1.el7_9
  • H
Cross-site Scripting (XSS)

<0:91.4.0-1.el7_9
  • H
Information Exposure

<0:91.4.0-1.el7_9
  • H
Unquoted Search Path or Element

<0:91.4.0-1.el7_9
  • H
Use After Free

<0:91.4.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.4.0-1.el7_9
  • H
Buffer Overflow

<0:91.4.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.4.0-1.el7_9
  • H
Buffer Overflow

<0:91.4.0-1.el7_9
  • H
Buffer Overflow

<0:115.10.0-1.el7_9
  • H
Use After Free

<0:115.10.0-1.el7_9
  • H
Integer Overflow or Wraparound

<0:115.10.0-1.el7_9
  • H
Use After Free

<0:115.10.0-1.el7_9
  • H
Out-of-bounds Read

<0:115.10.0-1.el7_9
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<0:115.10.0-1.el7_9
  • H
Resource Exhaustion

<0:115.10.0-1.el7_9
  • H
Product UI does not Warn User of Unsafe Actions

<0:115.10.0-1.el7_9
  • H
Use After Free

<0:91.3.0-1.el7_9
  • H
Buffer Overflow

<0:91.3.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.3.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.3.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:91.3.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.3.0-1.el7_9
  • H
Use After Free

<0:91.3.0-1.el7_9
  • H
Incorrect Permission Assignment for Critical Resource

<0:91.3.0-1.el7_9
  • H
Buffer Overflow

<0:78.14.0-1.el7_9
  • H
Buffer Overflow

<0:115.7.0-1.el7_9
  • H
Inadequate Encryption Strength

<0:115.7.0-1.el7_9
  • H
Improper Input Validation

<0:115.7.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:115.7.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:115.7.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:115.7.0-1.el7_9
  • H
Improper Input Validation

<0:115.7.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:115.7.0-1.el7_9
  • H
Out-of-bounds Write

<0:115.7.0-1.el7_9
  • H
Buffer Overflow

<0:91.2.0-4.el7_9
  • H
Buffer Overflow

<0:91.2.0-4.el7_9
  • H
Use After Free

<0:91.2.0-4.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.2.0-4.el7_9
  • H
Use After Free

<0:91.2.0-4.el7_9
  • H
Out-of-Bounds

<0:91.2.0-4.el7_9
  • H
Buffer Overflow

<0:78.13.0-2.el7_9
  • H
Out-of-Bounds

<0:78.13.0-2.el7_9
  • H
Time-of-check Time-of-use (TOCTOU)

<0:78.13.0-2.el7_9
  • H
Use After Free

<0:78.13.0-2.el7_9
  • H
Use After Free

<0:78.13.0-2.el7_9
  • H
Use of Uninitialized Resource

<0:78.13.0-2.el7_9
  • H
Buffer Overflow

<0:102.10.0-1.el7_9
  • H
Incorrect Calculation

<0:102.10.0-1.el7_9
  • H
Unrestricted Upload of File with Dangerous Type

<0:102.10.0-1.el7_9
  • H
Failure to Sanitize Special Element

<0:102.10.0-1.el7_9
  • H
Reachable Assertion

<0:102.10.0-1.el7_9
  • H
Out-of-Bounds

<0:102.10.0-1.el7_9
  • H
Direct Request ('Forced Browsing')

<0:102.10.0-1.el7_9
  • H
Double Free

<0:102.10.0-1.el7_9
  • H
Out-of-Bounds

<0:102.10.0-1.el7_9
  • H
Buffer Overflow

<0:78.5.0-1.el7_9
  • H
Improper Cross-boundary Removal of Sensitive Data

<0:78.5.0-1.el7_9
  • H
Improperly Implemented Security Check for Standard

<0:78.5.0-1.el7_9
  • H
Use After Free

<0:78.5.0-1.el7_9
  • H
Use After Free

<0:78.5.0-1.el7_9
  • H
Cross-site Scripting (XSS)

<0:78.5.0-1.el7_9
  • H
Cross-site Scripting (XSS)

<0:78.5.0-1.el7_9
  • H
User Interface (UI) Misrepresentation of Critical Information

<0:78.5.0-1.el7_9
  • H
Improper Validation of Integrity Check Value

<0:78.5.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:78.5.0-1.el7_9
  • H
Buffer Overflow

<0:78.11.0-3.el7_9
  • H
Buffer Overflow

<0:102.5.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:102.5.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:102.5.0-1.el7_9
  • H
Information Exposure

<0:102.5.0-1.el7_9
  • H
Information Exposure

<0:102.5.0-1.el7_9
  • H
Cross-site Scripting (XSS)

<0:102.5.0-1.el7_9
  • H
Sensitive Cookie with Improper SameSite Attribute

<0:102.5.0-1.el7_9
  • H
Use After Free

<0:102.5.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:102.5.0-1.el7_9
  • H
Use After Free

<0:102.5.0-1.el7_9
  • H
Use After Free

<0:102.5.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:102.5.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:102.5.0-1.el7_9
  • H
Out-of-Bounds

<0:78.9.0-1.el7_9
  • H
Buffer Overflow

<0:78.9.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:78.9.0-1.el7_9
  • H
Information Exposure

<0:78.9.0-1.el7_9
  • H
Out-of-bounds Read

<0:78.9.0-1.el7_9
  • H
Buffer Overflow

<0:91.10.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:91.10.0-1.el7_9
  • H
Use of Uninitialized Variable

<0:91.10.0-1.el7_9
  • H
Allocation of Resources Without Limits or Throttling

<0:91.10.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.10.0-1.el7_9
  • H
Buffer Overflow

<0:78.7.0-2.el7_9
  • H
Buffer Overflow

<0:91.10.0-1.el7_9
  • H
Null Byte Interaction Error (Poison Null Byte)

<0:78.7.0-2.el7_9
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<0:78.7.0-2.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:91.10.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:78.7.0-2.el7_9
  • H
Information Exposure

<0:78.7.0-2.el7_9
  • C
Use After Free

<0:78.4.1-1.el7_9
  • C
Use After Free

<0:78.6.1-1.el7_9
  • H
Buffer Overflow

<0:78.6.0-1.el7_9
  • H
Information Exposure

<0:78.6.0-1.el7_9
  • H
Information Exposure

<0:78.6.0-1.el7_9
  • H
Use After Free

<0:78.6.0-1.el7_9
  • H
Improper Input Validation

<0:78.6.0-1.el7_9
  • H
Buffer Overflow

<0:78.6.0-1.el7_9
  • H
Information Exposure

<0:78.6.0-1.el7_9
  • H
Buffer Overflow

<0:68.9.0-1.el7_8
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<0:68.9.0-1.el7_8
  • H
Use After Free

<0:68.9.0-1.el7_8
  • H
Use After Free

<0:68.12.0-1.el7_8
  • H
Incorrect Use of Privileged APIs

<0:68.12.0-1.el7_8
  • H
Integer Overflow or Wraparound

<0:78.10.0-1.el7_9
  • H
NULL Pointer Dereference

<0:78.10.0-1.el7_9
  • H
Arbitrary Argument Injection

<0:78.10.0-1.el7_9
  • H
Improper Preservation of Permissions

<0:78.10.0-1.el7_9
  • H
Improper Preservation of Permissions

<0:78.10.0-1.el7_9
  • H
Use After Free

<0:78.10.0-1.el7_9
  • H
Out-of-bounds Write

<0:78.10.0-1.el7_9
  • H
Information Exposure

<0:78.10.0-1.el7_9
  • H
Buffer Overflow

<0:91.5.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.5.0-1.el7_9
  • H
NULL Pointer Dereference

<0:91.5.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:91.5.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.5.0-1.el7_9
  • H
Buffer Overflow

<0:91.5.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.5.0-1.el7_9
  • H
Use After Free

<0:91.5.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.5.0-1.el7_9
  • H
Buffer Overflow

<0:91.5.0-1.el7_9
  • H
Use After Free

<0:91.5.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.5.0-1.el7_9
  • C
Use After Free

<0:68.6.1-1.el7_8
  • C
Use After Free

<0:68.6.1-1.el7_8
  • H
Buffer Overflow

<0:68.7.0-2.el7_8
  • H
Out-of-Bounds

<0:68.7.0-2.el7_8
  • H
Out-of-Bounds

<0:68.7.0-2.el7_8
  • H
Improper Following of a Certificate's Chain of Trust

<0:68.10.0-1.el7_8
  • H
Use After Free

<0:68.10.0-1.el7_8
  • H
Use After Free

<0:68.10.0-1.el7_8
  • H
Information Exposure

<0:68.10.0-1.el7_8
  • H
Out-of-Bounds

<0:68.10.0-1.el7_8
  • H
Buffer Overflow

<0:68.5.0-2.el7_7
  • H
Cross-site Scripting (XSS)

<0:68.5.0-2.el7_7
  • H
Out-of-bounds Write

<0:68.5.0-2.el7_7
  • H
Use After Free

<0:78.3.0-1.el7_9
  • H
Open Redirect

<0:78.3.0-1.el7_9
  • H
Cross-site Scripting (XSS)

<0:78.3.0-1.el7_9
  • H
Buffer Overflow

<0:78.3.0-1.el7_9
  • H
Improper Neutralization of Special Elements

<0:78.3.0-1.el7_9
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<0:78.3.0-1.el7_9
  • H
User Interface (UI) Misrepresentation of Critical Information

<0:78.3.0-1.el7_9
  • H
Incorrect Default Permissions

<0:78.3.0-1.el7_9
  • H
User Interface (UI) Misrepresentation of Critical Information

<0:78.3.0-1.el7_9
  • H
Out-of-bounds Read

<0:78.3.0-1.el7_9
  • H
User Interface (UI) Misrepresentation of Critical Information

<0:78.3.0-1.el7_9
  • H
Integer Overflow or Wraparound

<0:78.3.0-1.el7_9
  • C
Buffer Overflow

<0:68.3.0-1.el7_7
  • C
Use After Free

<0:68.3.0-1.el7_7
  • C
Use After Free

<0:68.3.0-1.el7_7
  • C
Use After Free

<0:68.3.0-1.el7_7
  • C
Buffer Overflow

<0:68.3.0-1.el7_7
  • H
Execution with Unnecessary Privileges

<0:60.9.0-1.el7_7
  • H
Use After Free

<0:60.9.0-1.el7_7
  • H
Use After Free

<0:60.9.0-1.el7_7
  • H
Cross-site Scripting (XSS)

<0:60.9.0-1.el7_7
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:60.9.0-1.el7_7
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:60.9.0-1.el7_7
  • H
Buffer Overflow

<0:60.9.0-1.el7_7
  • H
Missing Authorization

<0:60.9.0-1.el7_7
  • C
Reliance on Untrusted Inputs in a Security Decision

<0:60.8.0-1.el7_6
  • C
Inclusion of Functionality from Untrusted Control Sphere

<0:60.8.0-1.el7_6
  • C
Improper Neutralization of Special Elements

<0:60.8.0-1.el7_6
  • C
Cross-site Scripting (XSS)

<0:60.8.0-1.el7_6
  • C
Use After Free

<0:60.8.0-1.el7_6
  • C
Inclusion of Functionality from Untrusted Control Sphere

<0:60.8.0-1.el7_6
  • C
Improper Cross-boundary Removal of Sensitive Data

<0:60.8.0-1.el7_6
  • C
Buffer Overflow

<0:60.8.0-1.el7_6
  • C
Out-of-bounds Read

<0:60.2.2-1.el7_5
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

<0:60.2.2-1.el7_5
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

<0:68.4.1-1.el7_7
  • C
Buffer Overflow

<0:68.4.1-1.el7_7
  • C
Cross-site Scripting (XSS)

<0:68.4.1-1.el7_7
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

<0:68.4.1-1.el7_7
  • C
Cross-site Scripting (XSS)

<0:68.4.1-1.el7_7
  • C
Privilege Context Switching Error

<0:60.7.2-1.el7_6
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

<0:60.7.2-1.el7_6
  • C
Use After Free

<0:60.6.0-3.el7_6
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

<0:60.6.0-3.el7_6
  • C
Out-of-Bounds

<0:60.6.0-3.el7_6
  • C
Information Exposure

<0:60.6.0-3.el7_6
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

<0:60.6.0-3.el7_6
  • C
Use After Free

<0:60.6.0-3.el7_6
  • C
Buffer Overflow

<0:60.6.0-3.el7_6
  • C
Information Exposure

<0:60.6.0-3.el7_6
  • M
Improper Input Validation

<0:60.2.1-1.el7_5
  • M
Improper Cross-boundary Removal of Sensitive Data

<0:60.2.1-1.el7_5
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

<0:60.6.1-1.el7_6
  • C
Out-of-Bounds

<0:60.6.1-1.el7_6
  • C
Improper Authentication

<0:60.5.0-2.el7
  • C
Buffer Overflow

<0:60.5.0-2.el7
  • C
Use After Free

<0:60.5.0-2.el7
  • H
Use After Free

<0:52.7.3-1.el7_5
  • C
Missing Authorization

<0:60.3.0-1.el7_5
  • C
Improper Access Control

<0:60.3.0-1.el7_5
  • C
Improper Access Control

<0:60.3.0-1.el7_5
  • C
Integer Overflow or Wraparound

<0:60.3.0-1.el7_5
  • C
Race Condition

<0:60.3.0-1.el7_5
  • C
Buffer Overflow

<0:60.3.0-1.el7_5
  • C
Buffer Overflow

<0:60.3.0-1.el7_5
  • C
Information Exposure

<0:52.5.0-1.el7_4
  • C
Use After Free

<0:52.5.0-1.el7_4
  • C
Buffer Overflow

<0:52.5.0-1.el7_4
  • C
Inclusion of Functionality from Untrusted Control Sphere

<0:60.2.0-1.el7_5
  • C
Out-of-bounds Write

<0:60.2.0-1.el7_5
  • C
Use After Free

<0:60.2.0-1.el7_5
  • C
Use After Free

<0:60.2.0-1.el7_5
  • C
Buffer Overflow

<0:60.2.0-1.el7_5
  • C
Information Exposure

<0:60.2.0-1.el7_5
  • C
Heap-based Buffer Overflow

<0:52.7.2-1.el7_4
  • C
Buffer Overflow

<0:52.8.0-1.el7_5
  • C
Buffer Overflow

<0:52.8.0-1.el7_5
  • C
Missing Authorization

<0:52.8.0-1.el7_5
  • C
Integer Overflow or Wraparound

<0:52.8.0-1.el7_5
  • C
Eval Injection

<0:52.8.0-1.el7_5
  • C
Inclusion of Functionality from Untrusted Control Sphere

<0:52.8.0-1.el7_5
  • C
Use After Free

<0:52.8.0-1.el7_5
  • C
Use After Free

<0:52.8.0-1.el7_5
  • C
Buffer Overflow

<0:52.8.0-1.el7_5
  • C
User Interface (UI) Misrepresentation of Critical Information

<0:52.6.0-1.el7_4
  • C
Use After Free

<0:52.6.0-1.el7_4
  • C
Use After Free

<0:52.6.0-1.el7_4
  • C
Use After Free

<0:52.6.0-1.el7_4
  • C
Use After Free

<0:52.6.0-1.el7_4
  • C
Use After Free

<0:52.6.0-1.el7_4
  • C
Use After Free

<0:52.6.0-1.el7_4
  • C
Use After Free

<0:52.6.0-1.el7_4
  • C
Integer Overflow or Wraparound

<0:52.6.0-1.el7_4
  • C
Use After Free

<0:52.6.0-1.el7_4
  • C
Buffer Overflow

<0:52.6.0-1.el7_4
  • H
Improper Cross-boundary Removal of Sensitive Data

<0:52.5.1-1.el7_4
  • C
Buffer Overflow

<0:52.4.0-1.el7_4
  • C
Cross-site Scripting (XSS)

<0:52.4.0-1.el7_4
  • C
Use After Free

<0:52.4.0-1.el7_4
  • C
Use After Free

<0:52.4.0-1.el7_4
  • C
Download of Code Without Integrity Check

<0:52.4.0-1.el7_4
  • C
Buffer Overflow

<0:52.4.0-1.el7_4
  • C
Use After Free

<0:52.4.0-1.el7_4
  • C
Use After Free

<0:52.3.0-2.el7_4
  • C
Inclusion of Functionality from Untrusted Control Sphere

<0:52.3.0-2.el7_4
  • C
Incorrect Authorization

<0:52.3.0-2.el7_4
  • C
Use After Free

<0:52.3.0-2.el7_4
  • C
Use After Free

<0:52.3.0-2.el7_4
  • C
Use After Free

<0:52.3.0-2.el7_4
  • C
Arbitrary Command Injection

<0:52.3.0-2.el7_4
  • C
Out-of-bounds Read

<0:52.3.0-2.el7_4
  • C
Inclusion of Functionality from Untrusted Control Sphere

<0:52.3.0-2.el7_4
  • C
Incorrect Authorization

<0:52.3.0-2.el7_4
  • C
Out-of-bounds Read

<0:52.3.0-2.el7_4
  • C
Out-of-bounds Read

<0:52.3.0-2.el7_4
  • C
Use After Free

<0:52.3.0-2.el7_4
  • C
Out-of-Bounds

<0:52.3.0-2.el7_4
  • C
Out-of-bounds Read

<0:52.3.0-2.el7_4
  • C
Out-of-Bounds

<0:52.0-4.el7_3
  • C
Information Exposure

<0:52.0-4.el7_3
  • C
Information Exposure

<0:52.0-4.el7_3
  • C
DEPRECATED: Use of Uninitialized Resource

<0:52.0-4.el7_3
  • C
Use After Free

<0:52.0-4.el7_3
  • C
Use After Free

<0:52.0-4.el7_3
  • C
Error Handling

<0:52.0-4.el7_3
  • C
Out-of-Bounds

<0:52.0-4.el7_3
  • C
Out-of-Bounds

<0:52.0-4.el7_3
  • C
Buffer Overflow

<0:52.7.0-1.el7_4
  • C
Integer Overflow or Wraparound

<0:52.7.0-1.el7_4
  • C
Improper Cross-boundary Removal of Sensitive Data

<0:52.7.0-1.el7_4
  • C
Buffer Overflow

<0:52.7.0-1.el7_4
  • C
Out-of-bounds Write

<0:52.7.0-1.el7_4
  • C
Buffer Overflow

<0:52.7.0-1.el7_4
  • C
Buffer Overflow

<0:52.7.0-1.el7_4
  • C
Out-of-Bounds

<0:52.2.0-1.el7_3
  • C
Missing Initialization of a Variable

<0:52.2.0-1.el7_3
  • C
Out-of-bounds Read

<0:52.2.0-1.el7_3
  • C
Out-of-bounds Read

<0:52.2.0-1.el7_3
  • C
Heap-based Buffer Overflow

<0:52.2.0-1.el7_3
  • C
Heap-based Buffer Overflow

<0:52.2.0-1.el7_3
  • C
Out-of-bounds Read

<0:52.2.0-1.el7_3
  • C
Improper Input Validation

<0:52.2.0-1.el7_3
  • C
Out-of-bounds Read

<0:52.2.0-1.el7_3
  • C
Use After Free

<0:52.2.0-1.el7_3
  • C
Use After Free

<0:52.2.0-1.el7_3
  • C
Out-of-bounds Read

<0:52.2.0-1.el7_3
  • C
Use After Free

<0:52.2.0-1.el7_3
  • C
Use After Free

<0:52.2.0-1.el7_3
  • C
Use After Free

<0:45.7.0-2.el7_3
  • C
Use After Free

<0:52.2.0-1.el7_3
  • C
CVE-2017-5390

<0:45.7.0-2.el7_3
  • C
Use After Free

<0:52.2.0-1.el7_3
  • C
CVE-2017-5386

<0:45.7.0-2.el7_3
  • C
Use After Free

<0:52.2.0-1.el7_3
  • C
Improper Input Validation

<0:45.7.0-2.el7_3
  • C
Out-of-Bounds

<0:52.2.0-1.el7_3
  • C
Use After Free

<0:45.7.0-2.el7_3
  • C
Information Exposure

<0:45.7.0-2.el7_3
  • C
Use After Free

<0:45.7.0-2.el7_3
  • C
Out-of-Bounds

<0:45.7.0-2.el7_3
  • C
Out-of-Bounds

<0:45.7.0-2.el7_3
  • C
Integer Overflow or Wraparound

<0:52.0-5.el7_3
  • C
Out-of-Bounds

<0:52.1.0-2.el7_3
  • C
Out-of-Bounds

<0:52.1.0-2.el7_3
  • C
Cross-site Scripting (XSS)

<0:52.1.0-2.el7_3
  • C
Out-of-bounds Read

<0:52.1.0-2.el7_3
  • C
Out-of-Bounds

<0:52.1.0-2.el7_3
  • C
Use After Free

<0:52.1.0-2.el7_3
  • C
Out-of-Bounds

<0:52.1.0-2.el7_3
  • C
Incorrect Permission Assignment for Critical Resource

<0:52.1.0-2.el7_3
  • C
CVE-2017-5455

<0:52.1.0-2.el7_3
  • C
Information Exposure

<0:52.1.0-2.el7_3
  • C
Improper Input Validation

<0:52.1.0-2.el7_3
  • C
Improper Input Validation

<0:52.1.0-2.el7_3
  • C
Out-of-bounds Write

<0:52.1.0-2.el7_3
  • C
Use After Free

<0:52.1.0-2.el7_3
  • C
Out-of-bounds Read

<0:52.1.0-2.el7_3
  • C
Improper Validation of Array Index

<0:52.1.0-2.el7_3
  • C
Out-of-Bounds

<0:52.1.0-2.el7_3
  • C
Out-of-bounds Write

<0:52.1.0-2.el7_3
  • C
Use After Free

<0:52.1.0-2.el7_3
  • C
Use After Free

<0:52.1.0-2.el7_3
  • C
Use After Free

<0:52.1.0-2.el7_3
  • C
Use After Free

<0:52.1.0-2.el7_3
  • C
Use After Free

<0:52.1.0-2.el7_3
  • C
Out-of-bounds Write

<0:52.1.0-2.el7_3
  • C
Use After Free

<0:52.1.0-2.el7_3
  • C
Use After Free

<0:52.1.0-2.el7_3
  • C
Use After Free

<0:52.1.0-2.el7_3
  • C
Use After Free

<0:52.1.0-2.el7_3
  • C
Out-of-Bounds

<0:52.1.0-2.el7_3
  • C
Out-of-Bounds

<0:52.1.0-2.el7_3
  • C
Out-of-bounds Read

<0:52.1.0-2.el7_3
  • C
Stack-based Buffer Overflow

<0:52.1.0-2.el7_3
  • C
Out-of-bounds Read

<0:52.1.0-2.el7_3
  • C
Use After Free

<0:45.5.1-1.el7_3
  • C
Improper Input Validation

<0:45.4.0-1.el7_2
  • C
Use After Free

<0:45.4.0-1.el7_2
  • C
Use After Free

<0:45.4.0-1.el7_2
  • C
Out-of-Bounds

<0:45.4.0-1.el7_2
  • C
Use After Free

<0:45.4.0-1.el7_2
  • C
Use After Free

<0:45.4.0-1.el7_2
  • C
Use After Free

<0:45.4.0-1.el7_2