Unix
Vendor:
First CVE: Oct 13, 1995 · Active for 30 years
17
Total CVEs
More Total CVEs than 93% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Unix over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 13, 1995
30 years ago
Most Recent CVE
Jun 27, 2001
9,159 days ago
CVE Severity & Scoring
Unix17 CVEs
12%
29%
59%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown17 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown17 (100.0%)
User Interaction
None0 (0.0%)
Unknown17 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown17 (100.0%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-1999-0513MEDIUM ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service. | Jan 5, 1998 | 5.0 | 60 | NO | YES |
CVE-2001-0369HIGH Buffer overflow in lpsched on DGUX version R4.20MU06 and MU02 allows a local attacker to obtain root access via a long command line argument (non-existent printer name). | Jun 27, 2001 | 7.2 | 33 | NO | YES |
CVE-1999-0691HIGH Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name. | Sep 13, 1999 | 7.2 | 29 | NO | YES |
CVE-1999-0073HIGH Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access. | Oct 13, 1995 | 10.0 | 28 | NO | NO |
CVE-2001-0134HIGH Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execu | Mar 12, 2001 | 10.0 | 26 | NO | NO |
CVE-1999-0687HIGH The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands. | Sep 13, 1999 | 7.5 | 21 | NO | NO |
CVE-1999-0713HIGH The dtlogin program in Compaq Tru64 UNIX allows local users to gain root privileges. | Jun 11, 1999 | 7.2 | 18 | NO | NO |
CVE-1999-0406HIGH Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege. | Feb 19, 1999 | 7.2 | 18 | NO | NO |
CVE-1999-0358HIGH Digital Unix 4.0 has a buffer overflow in the inc program of the mh package. | Feb 1, 1999 | 7.2 | 18 | NO | NO |
CVE-1999-1458HIGH Buffer overflow in at program in Digital UNIX 4.0 allows local users to gain root privileges via a long command line argument. | Jan 25, 1999 | 7.2 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
17.6% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Unix
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| v4.0 | 1 | 4.6 | 0.3% | 0 | 0 |
| r4.20mu06 | 1 | 7.2 | 0.7% | 0 | 1 |
| mu02 | 1 | 7.2 | 0.7% | 0 | 1 |
| 5.0 | 1 | 10.0 | 4.0% | 0 | 0 |
| 4.0g | 1 | 10.0 | 4.0% | 0 | 0 |
| 4.0f | 4 | 7.8 | 2.1% | 0 | 1 |
| 4.0e | 4 | 5.9 | 0.5% | 0 | 1 |
| 4.0d | 6 | 6.0 | 12.5% | 0 | 2 |
| 4.0c | 4 | 5.4 | 17.9% | 0 | 1 |
| 4.0b | 5 | 5.7 | 14.4% | 0 | 1 |
| 4.0a | 4 | 5.4 | 17.9% | 0 | 1 |
| 4.0 | 7 | 5.9 | 11.2% | 0 | 1 |
| 3.2g | 3 | 5.7 | 24.7% | 0 | 1 |
| 3 | 1 | 2.1 | 0.6% | 0 | 0 |