ECMWF is a research organization that develops meteorological and climate data processing software, with a vulnerability footprint centered on visualization and data-manipulation tools such as Magics, Magics++, and Metview that handle scientific data streams. The durable signal reflects injection-oriented weakness classes across this specialized software stack, where output-neutralization and data-handling flaws have surfaced in its disclosure history; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ecmwf over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17515HIGH etc/ObjectList in Metview 4.7.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct | Dec 14, 2017 | 8.8 | 27 | NO | NO |
CVE-2010-3393MEDIUM magics-config in Magics++ 2.10.0 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the cu | Oct 20, 2010 | 6.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ecmwf.
Media articles that mention a CVE ID that affects a product developed by Ecmwf — matched by CVE ID, not by vendor name.