Dec's vulnerability profile clusters around its OpenVMS operating system and variants spanning VAX and Alpha architectures, a specialized platform with distinct deployment contexts and long operational lifespans. The observed weakness classes center on information disclosure and unclassified vulnerabilities, reflecting the complexity of legacy operating system internals and access-control mechanisms. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dec over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-1999-1395HIGH Vulnerability in Monitor utility (SYS$SHARE:SPISHR.EXE) in VMS 5.0 through 5.4-2 allows local users to gain privileges. | Nov 17, 1992 | 7.2 | 21 | NO | NO |
CVE-1999-1312HIGH Vulnerability in DEC OpenVMS VAX 5.5-2 through 5.0, and OpenVMS AXP 1.0, allows local users to gain system privileges. | Feb 24, 1993 | 7.2 | 20 | NO | NO |
CVE-2001-0845MEDIUM Vulnerability in DECwindows Motif Server on OpenVMS VAX or Alpha 6.2 through 7.3, and SEVMS VAX or Alpha 6.2, allows local users to gain access to unauthorized resources. | Dec 6, 2001 | 4.6 | 14 | NO | NO |
CVE-1999-1315MEDIUM Vulnerabilities in DECnet/OSI for OpenVMS before 5.8 on DEC Alpha AXP and VAX/VMS systems allow local users to gain privileges or cause a denial of service. | Dec 31, 1999 | 4.6 | 14 | NO | NO |
NET$SESSION_CONTROL.EXE in DECnet-Plus in OpenVMS ALPHA 7.3-2 and Alpha 8.2 writes a password to an audit log file when there is a successful connection after a "network breakin" e | Sep 5, 2006 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dec.
Media articles that mention a CVE ID that affects a product developed by Dec — matched by CVE ID, not by vendor name.