Cde maintains a narrowly scoped product with a specialized role in its deployment context. While the vendor's vulnerability disclosures are modestly represented in the landscape, they show a notable tendency to acquire public exploit code, reflecting the product's visibility and the nature of its attack surface. Live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cde over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-1999-0014HIGH Unauthorized privileged access or denial of service via dtappgather program in CDE. | Jan 21, 1998 | 7.2 | 30 | NO | YES |
CVE-1999-0691HIGH Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name. | Sep 13, 1999 | 7.2 | 29 | NO | YES |
CVE-1999-0689HIGH The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack. | Sep 13, 1999 | 7.2 | 27 | NO | YES |
CVE-1999-0112HIGH Buffer overflow in AIX dtterm program for the CDE. | May 1, 1997 | 7.2 | 27 | NO | YES |
CVE-1999-0687HIGH The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands. | Sep 13, 1999 | 7.5 | 21 | NO | NO |
CVE-1999-0690HIGH HP CDE program includes the current directory in root's PATH variable. | Jul 1, 1999 | 7.2 | 18 | NO | NO |
CVE-1999-0713HIGH The dtlogin program in Compaq Tru64 UNIX allows local users to gain root privileges. | Jun 11, 1999 | 7.2 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cde.
Media articles that mention a CVE ID that affects a product developed by Cde — matched by CVE ID, not by vendor name.