Patch
Vendor:
First CVE: Jan 21, 2015 · Active for 11 years
15
Total CVEs
More Total CVEs than 92% of tracked products
2.1
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Patch over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 21, 2015
11 years ago
Most Recent CVE
Jul 9, 2026
17 days ago
CVE Severity & Scoring
Patch15 CVEs
53%
47%
All CVEs352,719 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local9 (60.0%)
Network5 (33.3%)
Unknown1 (6.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (86.7%)
High1 (6.7%)
Unknown1 (6.7%)
User Interaction
None7 (46.7%)
Unknown1 (6.7%)
Required7 (46.7%)
Privileges Required
Low2 (13.3%)
High0 (0.0%)
None12 (80.0%)
Unknown1 (6.7%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6952HIGH A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6. | Feb 13, 2018 | 7.5 | 28 | NO | NO |
CVE-2018-6951HIGH An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_typ | Feb 13, 2018 | 7.5 | 28 | NO | NO |
CVE-2026-56289MEDIUM GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted pa | Jul 9, 2026 | 5.5 | 27 | NO | NO |
CVE-2026-56288MEDIUM GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can | Jul 9, 2026 | 5.5 | 27 | NO | NO |
CVE-2019-13638HIGH GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metachar | Jul 26, 2019 | 7.8 | 27 | NO | NO |
CVE-2018-1000156HIGH GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. | Apr 6, 2018 | 7.8 | 27 | NO | NO |
CVE-2018-20969HIGH do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is speci | Aug 16, 2019 | 7.8 | 26 | NO | NO |
CVE-2015-1395HIGH Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of th | Aug 25, 2017 | 7.5 | 23 | NO | NO |
CVE-2019-13636MEDIUM In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c. | Jul 17, 2019 | 5.9 | 22 | NO | NO |
CVE-2019-20633MEDIUM GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. | Mar 25, 2020 | 5.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Patch
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.7.6 | 2 | 7.8 | 5.0% | 0 | 0 |
| 2.7.1 | 1 | 4.3 | 6.1% | 0 | 0 |
| 2.7 | 1 | 5.5 | 0.7% | 0 | 0 |