Security Linux
Vendor:
First CVE: Nov 29, 2002 · Active for 23 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Security Linux over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 29, 2002
23 years ago
Most Recent CVE
Dec 4, 2005
7,537 days ago
CVE Severity & Scoring
Security Linux8 CVEs
25%
38%
38%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown8 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown8 (100.0%)
User Interaction
None0 (0.0%)
Unknown8 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (100.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2729HIGH The HTTP proxy in Astaro Security Linux 6.0 does not properly filter HTTP CONNECT requests to localhost, which allows remote attackers to bypass firewall rules and connect to local | Aug 30, 2005 | 7.5 | 31 | NO | YES |
CVE-2002-0029HIGH Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute ar | Nov 29, 2002 | 7.5 | 26 | NO | NO |
CVE-2005-3985HIGH The Internet Key Exchange version 1 (IKEv1) implementation in Astaro Security Linux before 6.102 allows remote attackers to cause a denial of service and possibly execute arbitrary | Dec 4, 2005 | 7.8 | 21 | NO | NO |
CVE-2005-3100MEDIUM Unspecified "PPTP Remote DoS Vulnerability" in Astaro Security Linux 4.027 allows attackers to cause a denial of service. | Sep 28, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-2730MEDIUM The HTTP proxy in Astaro Security Linux 6.0 allows remote attackers to obtain sensitive information via an invalid request, which reveals a Proxy-authorization string in an error m | Aug 30, 2005 | 5.0 | 15 | NO | NO |
CVE-2004-2251MEDIUM The PPTP server in Astaro Security Linux before 4.024 provides information about its version, which makes it easier for remote attackers to construct specialized attacks. | Dec 31, 2004 | 5.0 | 15 | NO | NO |
Directory traversal vulnerability in Astaro Security Linux 6.0, when using Webmin, allows remote authenticated webmin users to read arbitrary files via a .. (dot dot) in the wfe_d | Aug 30, 2005 | 2.1 | 11 | NO | NO |
Astaro Security Linux 2.016 creates world-writable files and directories, which allows local users to overwrite arbitrary files. | Dec 31, 2002 | 2.1 | 11 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Security Linux
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.101 | 1 | 7.8 | 4.3% | 0 | 0 |
| 6.002 | 1 | 7.8 | 4.3% | 0 | 0 |
| 6.001 | 4 | 5.6 | 3.3% | 0 | 1 |
| 4.027 | 1 | 5.0 | 1.8% | 0 | 0 |
| 4.023 | 1 | 5.0 | 2.1% | 0 | 0 |
| 4.022 | 1 | 5.0 | 2.1% | 0 | 0 |
| 4.021 | 1 | 5.0 | 2.1% | 0 | 0 |
| 4.020 | 1 | 5.0 | 2.1% | 0 | 0 |
| 4.019 | 1 | 5.0 | 2.1% | 0 | 0 |
| 4.018 | 1 | 5.0 | 2.1% | 0 | 0 |
| 4.017 | 1 | 5.0 | 2.1% | 0 | 0 |
| 3.2.11 | 1 | 7.5 | 9.9% | 0 | 0 |
| 3.2.10 | 1 | 7.5 | 9.9% | 0 | 0 |
| 3.2.0 | 1 | 7.5 | 9.9% | 0 | 0 |
| 2.0.30 | 1 | 7.5 | 9.9% | 0 | 0 |
| 2.0.27 | 1 | 7.5 | 9.9% | 0 | 0 |
| 2.0.26 | 1 | 7.5 | 9.9% | 0 | 0 |
| 2.0.25 | 1 | 7.5 | 9.9% | 0 | 0 |
| 2.0.24 | 1 | 7.5 | 9.9% | 0 | 0 |
| 2.0.23 | 1 | 7.5 | 9.9% | 0 | 0 |