Afflib
Vendor:
First CVE: Apr 30, 2007 · Active for 19 years
5
Total CVEs
Bottom 1%
2.5
Avg CVEs / Year
Bottom 1%
8.3
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Afflib over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 30, 2007
19 years ago
Most Recent CVE
Mar 11, 2018
3,057 days ago
CVE Severity & Scoring
Afflib5 CVEs
20%
80%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (20.0%)
Unknown4 (80.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (20.0%)
High0 (0.0%)
Unknown4 (80.0%)
User Interaction
None0 (0.0%)
Unknown4 (80.0%)
Required1 (20.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (20.0%)
Unknown4 (80.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2053HIGH Multiple stack-based buffer overflows in AFFLIB before 2.2.6 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) a long LastModif | Apr 30, 2007 | 10.0 | 31 | NO | NO |
CVE-2007-2352HIGH Multiple format string vulnerabilities in AFFLIB 2.2.6 allow remote attackers to execute arbitrary code via certain command line parameters, which are used in (1) warn and (2) err | Apr 30, 2007 | 10.0 | 26 | NO | NO |
CVE-2018-8050MEDIUM The af_get_page() function in lib/afflib_pages.cpp in AFFLIB (aka AFFLIBv3) through 3.7.16 allows remote attackers to cause a denial of service (segmentation fault) via a corrupt A | Mar 11, 2018 | 6.5 | 23 | NO | NO |
CVE-2007-2054HIGH Multiple format string vulnerabilities in AFFLIB before 2.2.6 allow remote attackers to execute arbitrary code via certain command line parameters, which are used in (1) warn and ( | Apr 30, 2007 | 7.5 | 20 | NO | NO |
CVE-2007-2055HIGH AFFLIB 2.2.8 and earlier allows attackers to execute arbitrary commands via shell metacharacters involving (1) certain command line parameters in tools/afconvert.cpp and (2) argume | Apr 30, 2007 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Afflib
Top CWEs
Versions
No cataloged versions.