Ccn Lite
Vendor:
First CVE: Jan 31, 2018 · Active for 8 years
17
Total CVEs
More Total CVEs than 93% of tracked products
17.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
9.1
Avg CVSS
Higher Avg CVSS than 84% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ccn Lite over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 31, 2018
8 years ago
Most Recent CVE
Jun 26, 2018
2,951 days ago
CVE Severity & Scoring
Ccn Lite17 CVEs
35%
65%
All CVEs352,708 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local1 (5.9%)
Network16 (94.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (88.2%)
Unknown0 (0.0%)
Required2 (11.8%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None17 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12468CRITICAL Buffer overflow in ccn-lite-ccnb2xml.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors involving the vallen and len variables. | Feb 7, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-7039CRITICAL CCN-lite 2.0.0 Beta allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact because the ccnl_ndntlv_prependBlob function in | Feb 14, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-12889CRITICAL An issue was discovered in CCN-lite 2.0.1. There is a heap-based buffer overflow in mkAddToRelayCacheRequest and in ccnl_populate_cache for an array lacking '\0' termination when r | Jun 26, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-6953CRITICAL In CCN-lite 2, the Parser of NDNTLV does not verify whether a certain component's length field matches the actual component length, which has a resultant buffer overflow and out-of | Feb 13, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-6948CRITICAL In CCN-lite 2, the function ccnl_prefix_to_str_detailed can cause a buffer overflow, when writing a prefix to the buffer buf. The maximal size of the prefix is CCNL_MAX_PREFIX_SIZE | Feb 13, 2018 | 9.8 | 29 | NO | NO |
CVE-2017-12466CRITICAL CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors related to ssl_halen when running ccn-lite-sim, which trigger an out-of-bounds access | Feb 7, 2018 | 9.8 | 28 | NO | NO |
CVE-2017-12472CRITICAL ccnl-ext-mgmt.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging missing NULL pointer checks after ccnl_malloc. | Feb 7, 2018 | 9.8 | 27 | NO | NO |
CVE-2017-12471CRITICAL The cnb_parse_lev function in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging failure to check for out-of-bounds conditions, which | Feb 7, 2018 | 9.8 | 27 | NO | NO |
CVE-2017-12470CRITICAL Integer overflow in the ndn_parse_sequence function in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors involving the typ and vallen v | Feb 7, 2018 | 9.8 | 27 | NO | NO |
CVE-2017-12469CRITICAL Buffer overflow in util/ccnl-common.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging incorrect memory allocation. | Feb 7, 2018 | 9.8 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Ccn Lite
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.1 | 1 | 9.8 | 1.7% | 0 | 0 |
| 2.0.0 | 4 | 9.6 | 1.5% | 0 | 0 |