OpenAnolis
First CVE: May 25, 2022Active for: 4 years
20
CVEs Published
More CVEs Published than 39% of tracked CNAs
6.7
Avg CVEs / Year
More Avg CVEs / Year than 41% of tracked CNAs
5.7
Avg CVSS Score
Higher Avg CVSS Score than 6% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by OpenAnolis as a CNA, 0.0% affect products that OpenAnolis develops as a vendor.
100.0%
Self-reported: 0Third-party: 20
Of all the CVEs published that affect products developed by OpenAnolis, 0.0% are self-published by OpenAnolis as a CNA.
100.0%
Self-published: 0Published by other CNAs: 1
Trends Over Time
The number and severity of CVEs published by OpenAnolis over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 25, 2022
4 years ago
Most Recent CVE
Feb 18, 2025
521 days ago
Top CVEs
All CVEs published by OpenAnolis as a CNA, regardless of affected vendor or product.
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-21803HIGH Use After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution of Code. This vulnerability is associated with program files | Jan 30, 2024 | 7.8 | 22 | NO | NO |
CVE-2025-1390MEDIUM The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as | Feb 18, 2025 | 6.1 | 21 | NO | NO |
CVE-2024-23307HIGH Integer Overflow or Wraparound vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (md, raid, raid5 modules) allows Forced Integer Overflow. | Jan 25, 2024 | 7.8 | 20 | NO | NO |
CVE-2022-36402MEDIUM An integer overflow vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx) | Sep 16, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-40133MEDIUM A use-after-free(UAF) vulnerability was found in function 'vmw_execbuf_tie_context' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dr | Sep 9, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-38457MEDIUM A use-after-free(UAF) vulnerability was found in function 'vmw_cmd_res_check' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dri/rend | Sep 9, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-38096MEDIUM A NULL pointer dereference vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (o | Sep 9, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-36280MEDIUM An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_kms.c in GPU component in the Linux kernel with device file '/dev/dri/rend | Sep 9, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-1678HIGH An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients | May 25, 2022 | 7.5 | 20 | NO | NO |
CVE-2024-24861MEDIUM A race condition was found in the Linux kernel's media/xc4000 device driver in xc4000 xc4000_get_frequency() function. This can result in return value overflow issue, possibly lead | Feb 5, 2024 | 6.3 | 19 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA20 CVEs
85%
15%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local15 (75.0%)
Network1 (5.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network4 (20.0%)
Attack Complexity
Low10 (50.0%)
High10 (50.0%)
Unknown0 (0.0%)
User Interaction
None18 (90.0%)
Unknown0 (0.0%)
Required2 (10.0%)
Privileges Required
Low15 (75.0%)
High0 (0.0%)
None5 (25.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by OpenAnolis as a CNA.
Media Mentions
Media articles that mention a CVE ID published by OpenAnolis as a CNA — matched by CVE ID, not by organization name.