Ehud Gavron maintains the traceroute family of network diagnostic tools, a narrowly scoped but foundational component in network troubleshooting and measurement infrastructure. Observed vulnerabilities in this toolset cluster around input handling and network-protocol parsing, areas typical of command-line utilities that process untrusted network responses. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ehud Gavron over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-1364HIGH Buffer overflow in the get_origin function in traceroute-nanog allows attackers to execute arbitrary code via long WHOIS responses. | Dec 23, 2002 | 7.2 | 27 | NO | YES |
CVE-2003-0453HIGH traceroute-nanog 6.1.1 allows local users to overwrite unauthorized memory and possibly execute arbitrary code via certain "nprobes" and "max_ttl" arguments that cause an integer o | Aug 7, 2003 | 10.0 | 25 | NO | NO |
CVE-2002-1386MEDIUM Buffer overflow in traceroute-nanog (aka traceroute-ng) may allow local users to execute arbitrary code via a long hostname argument. | Jan 2, 2003 | 4.6 | 14 | NO | NO |
CVE-2002-1387MEDIUM The spray mode in traceroute-nanog (aka traceroute-ng) may allow local users to overwrite arbitrary memory locations via an array index overflow using the nprobes (number of probes | Jan 2, 2003 | 4.6 | 14 | NO | NO |
CVE-2002-1051MEDIUM Format string vulnerability in TrACESroute 6.0 GOLD (aka NANOG traceroute) allows local users to execute arbitrary code via the -T (terminator) command line argument. | Oct 4, 2002 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ehud Gavron.
Media articles that mention a CVE ID that affects a product developed by Ehud Gavron — matched by CVE ID, not by vendor name.