Osf 1
Vendor:
First CVE: Oct 13, 1995 · Active for 30 years
9
Total CVEs
More Total CVEs than 86% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Osf 1 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 13, 1995
30 years ago
Most Recent CVE
Oct 4, 2002
8,694 days ago
CVE Severity & Scoring
Osf 19 CVEs
33%
67%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown9 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown9 (100.0%)
User Interaction
None0 (0.0%)
Unknown9 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown9 (100.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-1999-0128MEDIUM Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death. | Dec 18, 1996 | 5.0 | 63 | NO | YES |
CVE-1999-0073HIGH Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access. | Oct 13, 1995 | 10.0 | 28 | NO | NO |
CVE-2002-1129HIGH Buffer overflow in dxterm allows local users to execute arbitrary code via a long -xrm argument. | Oct 4, 2002 | 7.2 | 27 | NO | YES |
CVE-2002-1127HIGH Buffer overflow in uucp in Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long source (-s) command line parameter. | Oct 4, 2002 | 7.2 | 23 | NO | NO |
CVE-2002-1128HIGH Buffer overflow in inc mail utility for Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long MH environment variable. | Oct 4, 2002 | 7.2 | 23 | NO | NO |
CVE-1999-0131HIGH Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users. | Sep 11, 1996 | 7.2 | 20 | NO | NO |
CVE-1999-0138HIGH The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access. | Jun 26, 1996 | 7.2 | 19 | NO | NO |
CVE-1999-0303MEDIUM Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames. | May 21, 1998 | 4.6 | 14 | NO | NO |
CVE-1999-1103MEDIUM dxconsole in DEC OSF/1 3.2C and earlier allows local users to read arbitrary files by specifying the file with the -file parameter. | Apr 3, 1996 | 4.6 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
22.2% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Osf 1
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.0 | 1 | 7.2 | 0.5% | 0 | 0 |
| 3.2g | 3 | 7.2 | 0.7% | 0 | 1 |
| 3.2f | 3 | 7.2 | 0.7% | 0 | 1 |
| 3.2de2 | 3 | 7.2 | 0.7% | 0 | 1 |
| 3.2de1 | 3 | 7.2 | 0.7% | 0 | 1 |
| 3.2d | 3 | 7.2 | 0.7% | 0 | 1 |
| 3.2c | 3 | 7.2 | 0.7% | 0 | 1 |
| 3.2b | 3 | 7.2 | 0.7% | 0 | 1 |
| 3.2 | 4 | 7.9 | 1.3% | 0 | 1 |
| 3.0b | 3 | 7.2 | 0.7% | 0 | 1 |
| 3.0 | 4 | 7.9 | 1.3% | 0 | 1 |
| 2.0 | 1 | 10.0 | 3.1% | 0 | 0 |
| 1.3.3 | 1 | 5.0 | 74.7% | 0 | 1 |
| 1.3.2 | 1 | 7.2 | 0.6% | 0 | 0 |
| 1.3 | 2 | 8.6 | 1.9% | 0 | 0 |
| 1.2 | 1 | 10.0 | 3.1% | 0 | 0 |
| 1.1 | 1 | 4.6 | 0.4% | 0 | 0 |