Gt.M
Vendor:
First CVE: Apr 15, 2022 · Active for 4 years
28
Total CVEs
More Total CVEs than 97% of tracked products
28.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Gt.M over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 15, 2022
4 years ago
Most Recent CVE
Apr 15, 2022
1,565 days ago
CVE Severity & Scoring
Gt.M28 CVEs
89%
11%
All CVEs353,173 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network28 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None28 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None28 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44496CRITICAL An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size variable and buffer that is passed to | Apr 15, 2022 | 9.8 | 29 | NO | NO |
CVE-2021-44486CRITICAL An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can manipulate the value of a function pointer used in op_write in sr_port/op_write.c | Apr 15, 2022 | 9.8 | 29 | NO | NO |
CVE-2021-44488CRITICAL An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can control the size and input to calls to memcpy in op_fnfnumber in sr_port/op_fnfnum | Apr 15, 2022 | 9.1 | 27 | NO | NO |
CVE-2021-44509HIGH An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause an integer underflow of the size of calls to memse | Apr 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-44508HIGH An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of NULL checks in calls to ious_open in sr_unix/ious_open.c allows attackers to cras | Apr 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-44502HIGH An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size of a memset that occurs in calls to u | Apr 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-44494HIGH An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointe | Apr 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-44492HIGH An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, attackers can cause a type to be incorrectly initialized in the fu | Apr 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-44491HIGH An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c | Apr 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-44490HIGH An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c | Apr 15, 2022 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (28 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (28 CVEs).
Media Mentions
Signals from CVEs in this product scope (28 CVEs).
Top CNAs Publishing CVEs For Gt.M
Top CWEs
Versions
No cataloged versions.