Linux
Vendor:
First CVE: Mar 7, 2003 · Active for 23 years
159
Total CVEs
More Total CVEs than 99% of tracked products
11.4
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Linux over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 7, 2003
23 years ago
Most Recent CVE
Jan 15, 2025
554 days ago
CVE Severity & Scoring
Linux159 CVEs
17%
32%
50%
All CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (5.0%)
Network5 (3.1%)
Unknown146 (91.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (7.5%)
High1 (0.6%)
Unknown146 (91.8%)
User Interaction
None13 (8.2%)
Unknown146 (91.8%)
Required0 (0.0%)
Privileges Required
Low8 (5.0%)
High0 (0.0%)
None5 (3.1%)
Unknown146 (91.8%)
Top CVEs
Signals from CVEs in this product scope (159 CVEs).
159 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0608HIGH The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, | Dec 6, 2004 | 10.0 | 81 | NO | YES |
CVE-2002-1337HIGH Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments a | Mar 7, 2003 | 10.0 | 80 | NO | YES |
CVE-2004-1037HIGH The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string. | Mar 1, 2005 | 10.0 | 76 | NO | YES |
CVE-2024-12084CRITICAL A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIG | Jan 15, 2025 | 9.8 | 75 | NO | NO |
CVE-2003-0694HIGH The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c. | Oct 6, 2003 | 10.0 | 73 | NO | YES |
CVE-2004-0493MEDIUM The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error lead | Aug 6, 2004 | 6.4 | 72 | NO | YES |
CVE-2004-0932HIGH McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via | Jan 27, 2005 | 7.5 | 71 | NO | YES |
CVE-2004-0990HIGH Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code | Mar 1, 2005 | 10.0 | 50 | NO | YES |
CVE-2004-0386HIGH Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header. | May 4, 2004 | 10.0 | 49 | NO | YES |
CVE-2004-0333HIGH Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME ar | Nov 23, 2004 | 10.0 | 48 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (159 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
1.9% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
33 CVEs
20.8% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (159 CVEs).
Media Mentions
Signals from CVEs in this product scope (159 CVEs).
Top CNAs Publishing CVEs For Linux
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.3.30 | 1 | 4.6 | 0.4% | 0 | 0 |
| 2.2.28 | 1 | 4.6 | 0.4% | 0 | 0 |
| 2.1.30 | 1 | 4.6 | 0.4% | 0 | 0 |
| 1.4 | 51 | 7.0 | 11.8% | 0 | 21 |
| 1.2 | 12 | 7.0 | 11.1% | 0 | 3 |
| 1.1a | 12 | 7.0 | 11.1% | 0 | 3 |
| 0.7 | 11 | 7.0 | 11.9% | 0 | 3 |
| 0.5 | 11 | 7.0 | 11.9% | 0 | 3 |