Openvms

Vendor:

First CVE: May 2, 2005 · Active for 21 years

26
Total CVEs
More Total CVEs than 95% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
5.1
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Openvms over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Feb 7, 2018
3,089 days ago

CVE Severity & Scoring

Openvms26 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local1 (3.8%)
Network0 (0.0%)
Unknown25 (96.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (3.8%)
High0 (0.0%)
Unknown25 (96.2%)
User Interaction
None1 (3.8%)
Unknown25 (96.2%)
Required0 (0.0%)
Privileges Required
Low1 (3.8%)
High0 (0.0%)
None0 (0.0%)
Unknown25 (96.2%)

Top CVEs

Signals from CVEs in this product scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in the Process Software MultiNet finger service (aka FINGERD) for HP OpenVMS 8.3 allows remote attackers to execute arbitrary code via a long request st
Nov 18, 200810.039NOYES
An issue was discovered in OpenVMS through V8.4-2L2 on Alpha and through V8.4-2L1 on IA64, and VAX/VMS 4.0 and later. A malformed DCL command table may result in a buffer overflow
Feb 7, 20187.825NONO
The ACMELOGIN implementation in HP OpenVMS 8.3 and 8.4 on the Alpha platform, and 8.3, 8.3-1H1, and 8.4 on the Itanium platform, when the SYS$ACM system service is enabled, allows
May 18, 20126.923NONO
Unspecified vulnerability in the Auditing subsystem in HP OpenVMS 8.3, 8.2, 7.3-2, and earlier on the ALPHA platform, and 8.3-1H1, 8.3, 8.2-1, and earlier on the Itanium platform,
Jul 22, 20106.820NONO
Unspecified vulnerability in the DECnet-Plus 7.3-2 feature in DECnet/OSI 7.3-2 for OpenVMS ALPHA, and the DECnet-Plus 7.3 feature in DECnet/OSI 7.3 for OpenVMS VAX, allows attacker
Jan 9, 20077.520NONO
Unspecified vulnerability in HP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform on Integrity servers allows local users to gain privileges or cause a denial of service via un
Dec 22, 20105.719NONO
Unspecified vulnerability in Record Management Services (RMS) before VMS83A_RMS-V1100 for HP OpenVMS on the Alpha platform allows local users to gain privileges via unknown vectors
Feb 4, 20106.819NONO
HP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform and 7.3-2, 8.2, 8.3, and 8.4 on the Alpha platform does not properly implement the LOGIN and ACME_SERVER ACMELOGIN programs
Dec 13, 20125.018NONO
Unspecified vulnerability in HP OpenVMS 7.3-2 on the Alpha platform, 8.3 and 8.4 on the Alpha and IA64 platforms, and 8.3-1h1 on the IA64 platform allows local users to cause a den
Apr 19, 20124.918NONO
Stack-based buffer overflow in SMGSHR.EXE in OpenVMS for Integrity Servers 8.2-1, 8.3, and 8.3-1H1 and OpenVMS ALPHA 7.3-2, 8.2, and 8.3 allows local users to cause a denial of ser
Sep 11, 20087.218NONO

Exploit Exposure

Signals from CVEs in this product scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.8% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (26 CVEs).

Media Mentions

Signals from CVEs in this product scope (26 CVEs).

Top CNAs Publishing CVEs For Openvms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.455.20.9%00
8.3-1h175.50.7%00
8.3145.61.3%01
8.2-126.00.5%00
8.245.60.8%00
7.3-274.11.0%00
7.3_217.52.1%00
7.3-124.50.4%00
7.335.51.0%00
7.2-6c216.80.3%00
7.2-216.80.3%00
7.2-1h116.80.3%00
7.2-116.80.3%00
7.216.80.3%00
6.223.70.4%00
524.70.5%00