Extra Packages For Enterprise Linux

Vendor:

First CVE: Jan 16, 2020 · Active for 6 years

81
Total CVEs
More Total CVEs than 99% of tracked products
16.2
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 42% of tracked products
1.2%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Extra Packages For Enterprise Linux over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 16, 2020
6 years ago
Most Recent CVE
Jan 16, 2024
924 days ago

CVE Severity & Scoring

Extra Packages For Enterprise Linux81 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local36 (44.4%)
Network45 (55.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low78 (96.3%)
High3 (3.7%)
Unknown0 (0.0%)
User Interaction
None43 (53.1%)
Unknown0 (0.0%)
Required38 (46.9%)
Privileges Required
Low17 (21.0%)
High1 (1.2%)
None63 (77.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (81 CVEs).

81 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Jul 28, 20228.891YESNO
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or pri
Feb 26, 20207.537NOYES
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
May 30, 20239.835NONO
The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is
Apr 19, 20229.833NONO
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially
May 2, 20235.332NOYES
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certai
Dec 9, 20229.831NONO
A limited SQL injection risk was identified in the "browse list of users" site administration page.
Sep 30, 20229.830NONO
In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual a
Jan 31, 20229.130NONO
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The li
Nov 25, 20229.129NONO
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflo
Sep 8, 20218.829NONO

Exploit Exposure

Signals from CVEs in this product scope (81 CVEs).

CISA KEV
1 CVE
1.2% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
2.5% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (81 CVEs).

Media Mentions

Signals from CVEs in this product scope (81 CVEs).

Top CNAs Publishing CVEs For Extra Packages For Enterprise Linux

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.076.81.5%00
8.0526.92.9%11
7.0346.82.0%02