Condor

Vendor:

First CVE: Jul 31, 2008 · Active for 17 years

17
Total CVEs
More Total CVEs than 93% of tracked products
3.4
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Condor over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 31, 2008
17 years ago
Most Recent CVE
Jun 6, 2014
4,433 days ago

CVE Severity & Scoring

Condor17 CVEs
All CVEs352,719 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown17 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown17 (100.0%)
User Interaction
None0 (0.0%)
Unknown17 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown17 (100.0%)

Top CVEs

Signals from CVEs in this product scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Condor before 7.8.2 allows remote attackers to bypass host-based authentication and execute actions such as ALLOW_ADMINISTRATOR or ALLOW_WRITE by connecting from a system with a sp
Aug 25, 201210.033NONO
The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 does no properly check privileges, which allows remote attac
Jun 6, 201410.030NONO
Multiple unspecified vulnerabilities in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 have unknown impact and attack vectors related to "error checking of system calls."
Sep 28, 201210.028NONO
Multiple buffer overflows in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 have unknown impact and attack vectors.
Sep 28, 201210.028NONO
The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when they have weak permissio
Sep 28, 20126.421NONO
The command_give_request_ad function in condor_startd.V6/command.cpp Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 allows remote attackers to obtain sensitive information, and
Sep 28, 20125.820NONO
Condor before 7.0.4 does not properly handle wildcards in the ALLOW_WRITE, DENY_WRITE, HOSTALLOW_WRITE, or HOSTDENY_WRITE configuration variables in authorization policy lists, whi
Jul 31, 20087.520NONO
Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue jobs as an arbitrary user, and
Dec 23, 20096.518NONO
Condor before 7.0.5 does not properly handle when the configuration specifies overlapping netmasks in allow or deny rules, which causes the rule to be ignored and allows attackers
Oct 8, 20087.218NONO
Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local user
Feb 10, 20144.417NONO

Exploit Exposure

Signals from CVEs in this product scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (17 CVEs).

Media Mentions

Signals from CVEs in this product scope (17 CVEs).

Top CNAs Publishing CVEs For Condor

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.9.0110.02.5%00
7.8.4110.02.5%00
7.8.367.72.1%00
7.8.267.72.1%00
7.8.167.72.1%00
7.8.087.62.5%00
7.7.6110.02.5%00
7.7.5110.02.5%00
7.7.4110.02.5%00
7.7.3110.02.5%00
7.6.957.22.0%00
7.6.857.22.0%00
7.6.757.22.0%00
7.6.657.22.0%00
7.6.557.22.0%00
7.6.466.81.8%00
7.6.366.81.8%00
7.6.266.81.8%00
7.6.166.81.8%00
7.6.066.81.8%00