Openvms
Vendor:
First CVE: May 2, 2005 · Active for 21 years
26
Total CVEs
More Total CVEs than 95% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
5.1
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Openvms over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Feb 7, 2018
3,089 days ago
CVE Severity & Scoring
Openvms26 CVEs
23%
58%
19%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (3.8%)
Network0 (0.0%)
Unknown25 (96.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (3.8%)
High0 (0.0%)
Unknown25 (96.2%)
User Interaction
None1 (3.8%)
Unknown25 (96.2%)
Required0 (0.0%)
Privileges Required
Low1 (3.8%)
High0 (0.0%)
None0 (0.0%)
Unknown25 (96.2%)
Top CVEs
Signals from CVEs in this product scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5120HIGH Stack-based buffer overflow in the Process Software MultiNet finger service (aka FINGERD) for HP OpenVMS 8.3 allows remote attackers to execute arbitrary code via a long request st | Nov 18, 2008 | 10.0 | 39 | NO | YES |
CVE-2017-17482HIGH An issue was discovered in OpenVMS through V8.4-2L2 on Alpha and through V8.4-2L1 on IA64, and VAX/VMS 4.0 and later. A malformed DCL command table may result in a buffer overflow | Feb 7, 2018 | 7.8 | 25 | NO | NO |
CVE-2012-2010MEDIUM The ACMELOGIN implementation in HP OpenVMS 8.3 and 8.4 on the Alpha platform, and 8.3, 8.3-1H1, and 8.4 on the Itanium platform, when the SYS$ACM system service is enabled, allows | May 18, 2012 | 6.9 | 23 | NO | NO |
CVE-2010-1973MEDIUM Unspecified vulnerability in the Auditing subsystem in HP OpenVMS 8.3, 8.2, 7.3-2, and earlier on the ALPHA platform, and 8.3-1H1, 8.3, 8.2-1, and earlier on the Itanium platform, | Jul 22, 2010 | 6.8 | 20 | NO | NO |
CVE-2007-0139HIGH Unspecified vulnerability in the DECnet-Plus 7.3-2 feature in DECnet/OSI 7.3-2 for OpenVMS ALPHA, and the DECnet-Plus 7.3 feature in DECnet/OSI 7.3 for OpenVMS VAX, allows attacker | Jan 9, 2007 | 7.5 | 20 | NO | NO |
CVE-2010-4110MEDIUM Unspecified vulnerability in HP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform on Integrity servers allows local users to gain privileges or cause a denial of service via un | Dec 22, 2010 | 5.7 | 19 | NO | NO |
CVE-2010-0443MEDIUM Unspecified vulnerability in Record Management Services (RMS) before VMS83A_RMS-V1100 for HP OpenVMS on the Alpha platform allows local users to gain privileges via unknown vectors | Feb 4, 2010 | 6.8 | 19 | NO | NO |
CVE-2012-3277MEDIUM HP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform and 7.3-2, 8.2, 8.3, and 8.4 on the Alpha platform does not properly implement the LOGIN and ACME_SERVER ACMELOGIN programs | Dec 13, 2012 | 5.0 | 18 | NO | NO |
CVE-2012-0134MEDIUM Unspecified vulnerability in HP OpenVMS 7.3-2 on the Alpha platform, 8.3 and 8.4 on the Alpha and IA64 platforms, and 8.3-1h1 on the IA64 platform allows local users to cause a den | Apr 19, 2012 | 4.9 | 18 | NO | NO |
CVE-2008-4052HIGH Stack-based buffer overflow in SMGSHR.EXE in OpenVMS for Integrity Servers 8.2-1, 8.3, and 8.3-1H1 and OpenVMS ALPHA 7.3-2, 8.2, and 8.3 allows local users to cause a denial of ser | Sep 11, 2008 | 7.2 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (26 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.8% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (26 CVEs).
Media Mentions
Signals from CVEs in this product scope (26 CVEs).
Top CNAs Publishing CVEs For Openvms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.4 | 5 | 5.2 | 0.9% | 0 | 0 |
| 8.3-1h1 | 7 | 5.5 | 0.7% | 0 | 0 |
| 8.3 | 14 | 5.6 | 1.3% | 0 | 1 |
| 8.2-1 | 2 | 6.0 | 0.5% | 0 | 0 |
| 8.2 | 4 | 5.6 | 0.8% | 0 | 0 |
| 7.3-2 | 7 | 4.1 | 1.0% | 0 | 0 |
| 7.3_2 | 1 | 7.5 | 2.1% | 0 | 0 |
| 7.3-1 | 2 | 4.5 | 0.4% | 0 | 0 |
| 7.3 | 3 | 5.5 | 1.0% | 0 | 0 |
| 7.2-6c2 | 1 | 6.8 | 0.3% | 0 | 0 |
| 7.2-2 | 1 | 6.8 | 0.3% | 0 | 0 |
| 7.2-1h1 | 1 | 6.8 | 0.3% | 0 | 0 |
| 7.2-1 | 1 | 6.8 | 0.3% | 0 | 0 |
| 7.2 | 1 | 6.8 | 0.3% | 0 | 0 |
| 6.2 | 2 | 3.7 | 0.4% | 0 | 0 |
| 5 | 2 | 4.7 | 0.5% | 0 | 0 |