Linux

Vendor:

First CVE: Mar 7, 2003 · Active for 23 years

159
Total CVEs
More Total CVEs than 99% of tracked products
11.4
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Linux over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 7, 2003
23 years ago
Most Recent CVE
Jan 15, 2025
554 days ago

CVE Severity & Scoring

Linux159 CVEs
All CVEs352,101 CVEs
LowMediumHighCritical
Attack Vector
Local8 (5.0%)
Network5 (3.1%)
Unknown146 (91.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (7.5%)
High1 (0.6%)
Unknown146 (91.8%)
User Interaction
None13 (8.2%)
Unknown146 (91.8%)
Required0 (0.0%)
Privileges Required
Low8 (5.0%)
High0 (0.0%)
None5 (3.1%)
Unknown146 (91.8%)

Top CVEs

Signals from CVEs in this product scope (159 CVEs).

159 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier,
Dec 6, 200410.081NOYES
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments a
Mar 7, 200310.080NOYES
The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.
Mar 1, 200510.076NOYES
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIG
Jan 15, 20259.875NONO
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
Oct 6, 200310.073NOYES
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error lead
Aug 6, 20046.472NOYES
McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via
Jan 27, 20057.571NOYES
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code
Mar 1, 200510.050NOYES
Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.
May 4, 200410.049NOYES
Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME ar
Nov 23, 200410.048NOYES

Exploit Exposure

Signals from CVEs in this product scope (159 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
1.9% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
33 CVEs
20.8% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (159 CVEs).

Media Mentions

Signals from CVEs in this product scope (159 CVEs).

Top CNAs Publishing CVEs For Linux

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.3.3014.60.4%00
2.2.2814.60.4%00
2.1.3014.60.4%00
1.4517.011.8%021
1.2127.011.1%03
1.1a127.011.1%03
0.7117.011.9%03
0.5117.011.9%03