Extra Packages For Enterprise Linux
Vendor:
First CVE: Jan 16, 2020 · Active for 6 years
81
Total CVEs
More Total CVEs than 99% of tracked products
16.2
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 42% of tracked products
1.2%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Extra Packages For Enterprise Linux over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 16, 2020
6 years ago
Most Recent CVE
Jan 16, 2024
924 days ago
CVE Severity & Scoring
Extra Packages For Enterprise Linux81 CVEs
46%
40%
10%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local36 (44.4%)
Network45 (55.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low78 (96.3%)
High3 (3.7%)
Unknown0 (0.0%)
User Interaction
None43 (53.1%)
Unknown0 (0.0%)
Required38 (46.9%)
Privileges Required
Low17 (21.0%)
High1 (1.2%)
None63 (77.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (81 CVEs).
81 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2294HIGH Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Jul 28, 2022 | 8.8 | 91 | YES | NO |
CVE-2020-9274HIGH An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or pri | Feb 26, 2020 | 7.5 | 37 | NO | YES |
CVE-2023-34152CRITICAL A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured. | May 30, 2023 | 9.8 | 35 | NO | NO |
CVE-2022-25648CRITICAL The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is | Apr 19, 2022 | 9.8 | 33 | NO | NO |
CVE-2023-30943MEDIUM The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially | May 2, 2023 | 5.3 | 32 | NO | YES |
CVE-2022-4170CRITICAL The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certai | Dec 9, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-40315CRITICAL A limited SQL injection risk was identified in the "browse list of users" site administration page. | Sep 30, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-45079CRITICAL In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual a | Jan 31, 2022 | 9.1 | 30 | NO | NO |
CVE-2022-45152CRITICAL A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The li | Nov 25, 2022 | 9.1 | 29 | NO | NO |
CVE-2021-21897HIGH A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflo | Sep 8, 2021 | 8.8 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (81 CVEs).
CISA KEV
1 CVE
1.2% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
2.5% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (81 CVEs).
Media Mentions
Signals from CVEs in this product scope (81 CVEs).
Top CNAs Publishing CVEs For Extra Packages For Enterprise Linux
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0 | 7 | 6.8 | 1.5% | 0 | 0 |
| 8.0 | 52 | 6.9 | 2.9% | 1 | 1 |
| 7.0 | 34 | 6.8 | 2.0% | 0 | 2 |