Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Augeas

First CVE: Nov 23, 2013Active for: 13 yearsTotal CVEs: 6

Augeas is a configuration-file parsing and manipulation library deployed across Linux systems and management tooling, presenting a modest but strategically important attack surface where parsing errors can affect system configuration integrity. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and center on memory-safety and file-handling weakness classes including heap-based buffer overflows, path-traversal conditions, link-following flaws, and improper resource cleanup that are characteristic of C-based parsers operating on untrusted configuration data. Defenders should track this vendor's updates because flaws in configuration parsing can propagate through downstream automation and management platforms; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
4.7
Avg CVSS Score
Higher Avg CVSS Score than 8% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Augeas over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2013
12 years ago
Most Recent CVE
Mar 21, 2025
490 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-7555CRITICAL
Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would c
Aug 17, 20179.833NONO
CVE-2012-0787LOW
The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows local users to overwrit
Nov 23, 20133.716NONO
CVE-2025-2588LOW
A vulnerability has been found in Hercules Augeas 1.14.1 and classified as problematic. This vulnerability affects the function re_case_expand of the file src/fa.c. The manipulatio
Mar 21, 20253.315NONO
CVE-2012-6607LOW
The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augsav
Nov 23, 20133.315NONO
CVE-2012-0786LOW
The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augnew
Nov 23, 20133.315NONO
CVE-2013-6412MEDIUM
The transform_save function in transform.c in Augeas 1.0.0 through 1.1.0 does not properly calculate the permission values when the umask contains a "7," which causes world-writabl
Jan 23, 20144.614NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
67%
17%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumCritical
Attack Vector
Local1 (16.7%)
Network1 (16.7%)
Unknown4 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (33.3%)
High0 (0.0%)
Unknown4 (66.7%)
User Interaction
None2 (33.3%)
Unknown4 (66.7%)
Required0 (0.0%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None1 (16.7%)
Unknown4 (66.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Augeas.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Augeas — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Augeas's Products

View all 3 CNAs →

Top CWEs