openEuler
First CVE: Nov 23, 2020Active for: 6 years
39
CVEs Published
More CVEs Published than 52% of tracked CNAs
6.5
Avg CVEs / Year
More Avg CVEs / Year than 40% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by openEuler as a CNA, 20.5% affect products that openEuler develops as a vendor.
20.5%
79.5%
Self-reported: 8Third-party: 31
Of all the CVEs published that affect products developed by openEuler, 100.0% are self-published by openEuler as a CNA.
100.0%
Self-published: 8Published by other CNAs: 0
Trends Over Time
The number and severity of CVEs published by openEuler over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2020
5 years ago
Most Recent CVE
Apr 14, 2025
466 days ago
Top CVEs
All CVEs published by openEuler as a CNA, regardless of affected vendor or product.
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33643CRITICAL An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds r | Aug 10, 2022 | 9.1 | 32 | NO | NO |
CVE-2021-33640CRITICAL After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t | Dec 19, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-33657HIGH There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2.x to 2.0.18 versions. By crafting a malicious .BMP file, an attacker can cause the applic | Apr 1, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-33644HIGH An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longname, causing an out-of-bounds r | Aug 10, 2022 | 8.1 | 27 | NO | NO |
CVE-2021-33646HIGH The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak. | Aug 10, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-33645HIGH The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak. | Aug 10, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-33658HIGH atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate the local privilege or modify any file. Authentication is n | Mar 11, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-33639HIGH REMAP cmd of SVM driver can be used to remap read only memory as read-write, then cause read only memory/file modified. | Mar 8, 2023 | 7.5 | 24 | NO | NO |
CVE-2021-33641HIGH When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses the released memory (use after free). | Jan 20, 2023 | 7.8 | 24 | NO | NO |
CVE-2021-33656MEDIUM When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds. | Jul 18, 2022 | 6.8 | 24 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA39 CVEs
28%
67%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local19 (48.7%)
Network19 (48.7%)
Unknown0 (0.0%)
Physical1 (2.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low37 (94.9%)
High2 (5.1%)
Unknown0 (0.0%)
User Interaction
None30 (76.9%)
Unknown0 (0.0%)
Required9 (23.1%)
Privileges Required
Low8 (20.5%)
High6 (15.4%)
None25 (64.1%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (39 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by openEuler as a CNA.
Media Mentions
Media articles that mention a CVE ID published by openEuler as a CNA — matched by CVE ID, not by organization name.