Gurum's vulnerability profile centers on its GurumDDS product, a middleware platform for distributed data systems, where the observed exposure reflects memory-safety challenges inherent to native implementations. The recurring weakness classes—heap-based buffer overflows and incorrect buffer-size calculations—are characteristic of the parser and serialization logic required in data-distribution middleware. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gurum over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-38423CRITICAL All versions of GurumDDS improperly calculate the size to be used when allocating the buffer, which may result in a buffer overflow. | May 5, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-38439CRITICAL All versions of GurumDDS are vulnerable to heap-based buffer overflow, which may cause a denial-of-service condition or remotely execute arbitrary code. | May 5, 2022 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gurum.
Media articles that mention a CVE ID that affects a product developed by Gurum — matched by CVE ID, not by vendor name.