Engardelinux is a specialized Linux distribution vendor focused on hardened and security-oriented operating system products, with a narrow but prominent footprint in the defensive-security landscape. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, while recurring weakness classes center on boundary-condition errors such as off-by-one flaws that are characteristic of low-level system and kernel-oriented code. Defenders tracking this vendor should treat disclosures as high-priority for deployed hardened-Linux environments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Engardelinux over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0083CRITICAL Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges. | Mar 15, 2002 | 9.8 | 48 | NO | YES |
CVE-2003-0101HIGH miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded string | Mar 3, 2003 | 10.0 | 44 | NO | YES |
CVE-2002-0002HIGH Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code. | Jan 31, 2002 | 7.5 | 36 | NO | YES |
CVE-2003-0962HIGH Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail. | Dec 15, 2003 | 7.5 | 30 | NO | NO |
CVE-2001-1240HIGH The default configuration of sudo in Engarde Secure Linux 1.0.1 allows any user in the admin group to run certain commands that could be leveraged to gain full root access. | Jul 11, 2001 | 10.0 | 25 | NO | NO |
CVE-2001-0739HIGH Guardian Digital WebTool in EnGarde Secure Linux 1.0.1 allows restarted services to inherit some environmental variables, which could allow local users to gain root privileges. | Oct 18, 2001 | 7.2 | 18 | NO | NO |
Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack. | Oct 18, 2001 | 2.1 | 17 | NO | YES |
The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this is | Aug 6, 2004 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Engardelinux.
Media articles that mention a CVE ID that affects a product developed by Engardelinux — matched by CVE ID, not by vendor name.