Inetutils

Vendor:

First CVE: Dec 31, 2004 · Active for 21 years

9
Total CVEs
More Total CVEs than 86% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
11.1%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Inetutils over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Mar 16, 2026
131 days ago

CVE Severity & Scoring

Inetutils9 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local2 (22.2%)
Network5 (55.6%)
Unknown2 (22.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (77.8%)
High0 (0.0%)
Unknown2 (22.2%)
User Interaction
None5 (55.6%)
Unknown2 (22.2%)
Required2 (22.2%)
Privileges Required
Low2 (22.2%)
High0 (0.0%)
None5 (55.6%)
Unknown2 (22.2%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Jan 21, 20269.899YESYES
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU
Dec 25, 201110.092NOYES
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is
Mar 13, 20269.867NOYES
telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-l
Feb 27, 20267.826NONO
telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the te
Aug 30, 20227.526NONO
Buffer overflow in the TFTP client in InetUtils 1.4.2 allows remote malicious DNS servers to execute arbitrary code via a large DNS response that is handled by the gethostbyname fu
Dec 31, 20047.525NONO
The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284
Sep 3, 20216.523NONO
GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for exa
Aug 14, 20237.822NONO
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.
Mar 16, 20264.719NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
1 CVE
11.1% of CVEs· 97th percentile
Metasploit
2 CVEs
22.2% of CVEs· 97th percentile
Nuclei
1 CVE
11.1% of CVEs· 97th percentile
ExploitDB
3 CVEs
33.3% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Inetutils

Top CWEs

Versions

No cataloged versions.