Linux
Vendor:
First CVE: Jul 16, 2000 · Active for 26 years
66
Total CVEs
More Total CVEs than 98% of tracked products
7.3
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Linux over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 16, 2000
26 years ago
Most Recent CVE
Mar 20, 2013
4,874 days ago
CVE Severity & Scoring
Linux66 CVEs
15%
30%
53%
All CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network1 (1.5%)
Unknown65 (98.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (1.5%)
High0 (0.0%)
Unknown65 (98.5%)
User Interaction
None1 (1.5%)
Unknown65 (98.5%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (1.5%)
Unknown65 (98.5%)
Top CVEs
Signals from CVEs in this product scope (66 CVEs).
66 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0780HIGH Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a lon | Sep 22, 2003 | 9.0 | 75 | NO | YES |
CVE-2000-0666HIGH rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges. | Jul 16, 2000 | 10.0 | 52 | NO | YES |
CVE-2004-0557HIGH Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV | Aug 6, 2004 | 10.0 | 48 | NO | YES |
CVE-2002-0083CRITICAL Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges. | Mar 15, 2002 | 9.8 | 48 | NO | YES |
CVE-2001-0136MEDIUM Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly ins | Mar 12, 2001 | 5.0 | 45 | NO | YES |
CVE-2000-0844HIGH Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via fun | Nov 14, 2000 | 10.0 | 44 | NO | YES |
CVE-2004-1029HIGH The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java | Mar 1, 2005 | 9.3 | 41 | NO | YES |
CVE-2001-0690HIGH Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker to execute arbitrary code via format st | Sep 20, 2001 | 7.5 | 38 | NO | YES |
CVE-2004-0882HIGH Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a | Jan 27, 2005 | 10.0 | 37 | NO | NO |
CVE-2004-0902HIGH Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of ser | Jan 27, 2005 | 10.0 | 35 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (66 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
19 CVEs
28.8% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (66 CVEs).
Media Mentions
Signals from CVEs in this product scope (66 CVEs).
Top CNAs Publishing CVEs For Linux
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| prg_graficos | 1 | 7.5 | 4.6% | 0 | 1 |
| graficas | 2 | 6.0 | 7.8% | 0 | 2 |
| ecommerce | 3 | 6.5 | 6.8% | 0 | 3 |
| 9.0 | 26 | 7.1 | 8.0% | 0 | 3 |
| 8.0 | 7 | 5.8 | 18.4% | 0 | 4 |
| 7.0 | 7 | 6.7 | 17.2% | 0 | 3 |
| 6.0 | 8 | 5.9 | 3.1% | 0 | 3 |
| 5.1 | 14 | 6.1 | 5.5% | 0 | 8 |
| 5.0 | 15 | 6.3 | 5.3% | 0 | 7 |
| 4.2 | 12 | 6.4 | 5.1% | 0 | 6 |
| 4.1 | 11 | 6.3 | 5.6% | 0 | 6 |
| 4.0es | 9 | 6.1 | 6.6% | 0 | 6 |
| 4.0 | 9 | 6.1 | 6.6% | 0 | 6 |
| 10.0 | 33 | 7.1 | 5.5% | 0 | 5 |
| 10 | 2 | 3.5 | 1.8% | 0 | 1 |