Hesiod Project maintains a narrowly scoped name-service library that provides distributed user and group information resolution, historically used in Unix and Linux environments for authentication and directory lookups. The vendor's vulnerability disclosures reflect the input-parsing and protocol-handling demands of a resolver component; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hesiod Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10152CRITICAL The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote atta | Mar 28, 2017 | 9.8 | 34 | NO | NO |
CVE-2016-10151HIGH The hesiod_init function in lib/hesiod.c in Hesiod 3.2.1 compares EUID with UID to determine whether to use configurations from environment variables, which allows local users to g | Mar 1, 2017 | 7.0 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hesiod Project.
Media articles that mention a CVE ID that affects a product developed by Hesiod Project — matched by CVE ID, not by vendor name.