Page tree

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

CVE IdentifierHighest SeverityVulnerable PackageDate Reported3rd Party Patch Available?Latest vulnerable FAMNotes on vulnerability

Resloved Resolved FAM Version

FAM GA
CVE-2020-22218highlibssh2-1.8.0-4.el7.x86_6408/22/2023awaiting patch4.9.0.2An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.

critical

postgresql-42.2.2.jar

(lumeta-api RPM)

  • 02/02/2022
  • 03/10/2022
  • 08/30/2018
  • 08/03/2022
  • 06/04/2020
  • 11/23/2022
postgresql-42.6.0.jar4.9.0.2Various issues regarding PostgreSQL's official JDBC driver.4.10
CVE-2023-38325high

cryptography-40.0.2-cp36-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
(python_wmic RPM)

07/14/2023awaiting patch4.9.0.2Mishandles SSH certificates that have critical options.

CVE-2023-2828

highbind-export-libs-9.11.4-26.P2.el7_9.13.x86_64
bind-libs-lite-9.11.4-26.P2.el7_9.13.x86_64
bind-utils-9.11.4-26.P2.el7_9.13.x86_64
bind-license-9.11.4-26.P2.el7_9.13.noarch
bind-libs-9.11.4-26.P2.el7_9.13.x86_64
06/21/2023awaiting patch4.9.0.2The effectiveness of the cache-cleaning algorithm used in `named` can be severely diminished by querying the resolver for specific RRsets in a certain order, effectively allowing the configured `max-cache-size` limit to be significantly exceeded.

CVE-2023-30861high

Flask-2.0.3-py3-none-any.whl

05/02/2023awaiting patch4.9.0.2A response containing data intended for one client may be cached and subsequently sent by the proxy to other clients

CVE-2023-25577
CVE-2023-23934
high
Werkzeug-2.0.3-py3-none-any.whl
02/14/2023awaiting patch4.9.0.2Various werkzeug issues

CVE-2019-19919 
CVE-2021-23369
CVE-2021-23383
WS-2020-0450
WS-2019-0064
CVE-2019-20920
WS-2019-0103

CVE-2015-8861

critical
handlebars-1.3.0.js
(lumeta-api RPM)
12/20/2019handlebars-v4.7.8.js4.9.0.2Various handlebars issues4.10
CVE-2023-37920
CVE-2022-23491
critical
certifi-2021.10.8-py2.py3-none-any.whl
07/25/2023certifi-2023.7.22-py3-none-any.whl4.9.0.2Various certifi issues4.10

...