Berkeley's vulnerability footprint centers on a small set of academic and research-oriented projects, including the distributed computing platform BOINC and its associated infrastructure, alongside utility software such as the PMake build tool and Nvi text editor. The observed weakness classes span authentication issues, cross-site scripting in web-facing components, and miscellaneous categorization, reflecting the heterogeneous nature of these community-maintained tools; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Berkeley over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0915HIGH Format string vulnerability in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via format specifiers in the check argument of a shell | Nov 21, 2001 | 7.2 | 27 | NO | YES |
CVE-2001-0916HIGH Buffer overflow in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via a long check argument of a shell definition. | Nov 21, 2001 | 7.2 | 27 | NO | YES |
CVE-2007-4899MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Boinc Forum 5.10.20 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to for | Sep 14, 2007 | 4.3 | 21 | NO | YES |
CVE-2009-0126MEDIUM The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the O | Jan 15, 2009 | 5.0 | 15 | NO | NO |
nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover. | Dec 30, 1999 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Berkeley.
Media articles that mention a CVE ID that affects a product developed by Berkeley — matched by CVE ID, not by vendor name.