The Cron Project maintains a narrowly scoped scheduling utility whose vulnerability surface reflects the resource-management and file-access complexity inherent to a long-running daemon process, with observed weakness classes including resource exhaustion, link following, null-pointer dereferences, and improper return-value handling. Treat this as a compact vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cron Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9525MEDIUM In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via | Jun 9, 2017 | 6.7 | 23 | NO | NO |
CVE-2019-9705MEDIUM Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (memory consumption) via a large crontab file because an unlimited number of lines i | Mar 12, 2019 | 5.5 | 16 | NO | NO |
CVE-2019-9704MEDIUM Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not check | Mar 12, 2019 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cron Project.
Media articles that mention a CVE ID that affects a product developed by Cron Project — matched by CVE ID, not by vendor name.