Unix

Vendor:

First CVE: Oct 13, 1995 · Active for 30 years

17
Total CVEs
More Total CVEs than 93% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Unix over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 13, 1995
30 years ago
Most Recent CVE
Jun 27, 2001
9,159 days ago

CVE Severity & Scoring

Unix17 CVEs
All CVEs352,708 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown17 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown17 (100.0%)
User Interaction
None0 (0.0%)
Unknown17 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown17 (100.0%)

Top CVEs

Signals from CVEs in this product scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
Jan 5, 19985.060NOYES
Buffer overflow in lpsched on DGUX version R4.20MU06 and MU02 allows a local attacker to obtain root access via a long command line argument (non-existent printer name).
Jun 27, 20017.233NOYES
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
Sep 13, 19997.229NOYES
Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.
Oct 13, 199510.028NONO
Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execu
Mar 12, 200110.026NONO
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
Sep 13, 19997.521NONO
The dtlogin program in Compaq Tru64 UNIX allows local users to gain root privileges.
Jun 11, 19997.218NONO
Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege.
Feb 19, 19997.218NONO
Digital Unix 4.0 has a buffer overflow in the inc program of the mh package.
Feb 1, 19997.218NONO
Buffer overflow in at program in Digital UNIX 4.0 allows local users to gain root privileges via a long command line argument.
Jan 25, 19997.218NONO

Exploit Exposure

Signals from CVEs in this product scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
17.6% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (17 CVEs).

Media Mentions

Signals from CVEs in this product scope (17 CVEs).

Top CNAs Publishing CVEs For Unix

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
v4.014.60.3%00
r4.20mu0617.20.7%01
mu0217.20.7%01
5.0110.04.0%00
4.0g110.04.0%00
4.0f47.82.1%01
4.0e45.90.5%01
4.0d66.012.5%02
4.0c45.417.9%01
4.0b55.714.4%01
4.0a45.417.9%01
4.075.911.2%01
3.2g35.724.7%01
312.10.6%00