Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Conectiva

First CVE: Jul 16, 2000Active for: 26 yearsTotal CVEs: 66
60.4
VTI Score
TOP TARGET

Conectiva's vulnerability profile centers on its Linux distribution, which historically served as a widely deployed platform across Latin American and enterprise environments. The vendor's disclosures reflect the characteristic attack surface of a Linux operating system: a spectrum of low-level memory-safety and input-handling weaknesses including buffer overflows, improper input validation, and link-resolution flaws endemic to native system software. Public exploit code frequently becomes available for vulnerabilities of these classes, reflecting the transparency of open-source development and the appeal of kernel and core-utility targets. Defenders relying on this distribution should track upstream Linux kernel and component vulnerabilities closely, as patches flow through the Conectiva release cycle; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
66
Total CVEs
More Total CVEs than 99% of tracked vendors
7.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Conectiva over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 16, 2000
26 years ago
Most Recent CVE
Mar 20, 2013
4,874 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (66 CVEs).

66 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2003-0780HIGH
Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a lon
Sep 22, 20039.075NOYES
CVE-2000-0666HIGH
rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges.
Jul 16, 200010.052NOYES
CVE-2004-0557HIGH
Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV
Aug 6, 200410.048NOYES
CVE-2002-0083CRITICAL
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
Mar 15, 20029.848NOYES
CVE-2001-0136MEDIUM
Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly ins
Mar 12, 20015.045NOYES
CVE-2000-0844HIGH
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via fun
Nov 14, 200010.044NOYES
CVE-2004-1029HIGH
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java
Mar 1, 20059.341NOYES
CVE-2001-0690HIGH
Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker to execute arbitrary code via format st
Sep 20, 20017.538NOYES
CVE-2004-0882HIGH
Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a
Jan 27, 200510.037NONO
CVE-2004-0902HIGH
Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of ser
Jan 27, 200510.035NONO
View all 66 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products66 CVEs
15%
30%
53%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network1 (1.5%)
Unknown65 (98.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (1.5%)
High0 (0.0%)
Unknown65 (98.5%)
User Interaction
None1 (1.5%)
Unknown65 (98.5%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (1.5%)
Unknown65 (98.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (66 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
19 CVEs
28.8% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Conectiva.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Conectiva — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Conectiva's Products

View all 3 CNAs →

Top CWEs