Security Linux

Vendor:

First CVE: Nov 29, 2002 · Active for 23 years

8
Total CVEs
More Total CVEs than 85% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Security Linux over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 29, 2002
23 years ago
Most Recent CVE
Dec 4, 2005
7,537 days ago

CVE Severity & Scoring

Security Linux8 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown8 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown8 (100.0%)
User Interaction
None0 (0.0%)
Unknown8 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (100.0%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The HTTP proxy in Astaro Security Linux 6.0 does not properly filter HTTP CONNECT requests to localhost, which allows remote attackers to bypass firewall rules and connect to local
Aug 30, 20057.531NOYES
Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute ar
Nov 29, 20027.526NONO
The Internet Key Exchange version 1 (IKEv1) implementation in Astaro Security Linux before 6.102 allows remote attackers to cause a denial of service and possibly execute arbitrary
Dec 4, 20057.821NONO
Unspecified "PPTP Remote DoS Vulnerability" in Astaro Security Linux 4.027 allows attackers to cause a denial of service.
Sep 28, 20055.015NONO
The HTTP proxy in Astaro Security Linux 6.0 allows remote attackers to obtain sensitive information via an invalid request, which reveals a Proxy-authorization string in an error m
Aug 30, 20055.015NONO
The PPTP server in Astaro Security Linux before 4.024 provides information about its version, which makes it easier for remote attackers to construct specialized attacks.
Dec 31, 20045.015NONO
Directory traversal vulnerability in Astaro Security Linux 6.0, when using Webmin, allows remote authenticated webmin users to read arbitrary files via a .. (dot dot) in the wfe_d
Aug 30, 20052.111NONO
Astaro Security Linux 2.016 creates world-writable files and directories, which allows local users to overwrite arbitrary files.
Dec 31, 20022.111NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Security Linux

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.10117.84.3%00
6.00217.84.3%00
6.00145.63.3%01
4.02715.01.8%00
4.02315.02.1%00
4.02215.02.1%00
4.02115.02.1%00
4.02015.02.1%00
4.01915.02.1%00
4.01815.02.1%00
4.01715.02.1%00
3.2.1117.59.9%00
3.2.1017.59.9%00
3.2.017.59.9%00
2.0.3017.59.9%00
2.0.2717.59.9%00
2.0.2617.59.9%00
2.0.2517.59.9%00
2.0.2417.59.9%00
2.0.2317.59.9%00