Argus
Vendor:
First CVE: Oct 6, 2011 · Active for 14 years
10
Total CVEs
More Total CVEs than 88% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Argus over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 6, 2011
14 years ago
Most Recent CVE
Sep 17, 2018
2,868 days ago
CVE Severity & Scoring
Argus10 CVEs
100%
All CVEs352,427 CVEs
45%
40%
11%
High
Attack Vector
Local9 (90.0%)
Network0 (0.0%)
Unknown1 (10.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High0 (0.0%)
Unknown1 (10.0%)
User Interaction
None0 (0.0%)
Unknown1 (10.0%)
Required9 (90.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (90.0%)
Unknown1 (10.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-3332HIGH Stack-based buffer overflow in Iceni Argus 6.20 and earlier and Infix 5.04 allows remote attackers to execute arbitrary code via a crafted PDF document that uses flate compression. | Oct 6, 2011 | 10.0 | 32 | NO | NO |
CVE-2016-8387HIGH An exploitable heap-based buffer overflow exists in Iceni Argus. When it attempts to convert a malformed PDF with an object encoded w/ multiple encoding types terminating with an L | Feb 27, 2017 | 7.8 | 26 | NO | NO |
CVE-2016-8386HIGH An exploitable heap-based buffer overflow exists in Iceni Argus. When it attempts to convert a PDF containing a malformed font to XML, the tool will attempt to use a size out of th | Feb 27, 2017 | 7.8 | 26 | NO | NO |
CVE-2017-2777HIGH An exploitable heap overflow vulnerability exists in the ipStringCreate function of Iceni Argus Version 6.6.05. A specially crafted pdf file can cause an integer overflow resulting | Sep 17, 2018 | 7.8 | 22 | NO | NO |
CVE-2016-8335HIGH An exploitable stack based buffer overflow vulnerability exists in the ipNameAdd functionality of Iceni Argus Version 6.6.04 (Sep 7 2012) NK - Linux x64 and Version 6.6.04 (Nov 14 | Oct 28, 2016 | 7.8 | 22 | NO | NO |
CVE-2016-8333HIGH An exploitable stack-based buffer overflow vulnerability exists in the ipfSetColourStroke functionality of Iceni Argus version 6.6.04 A specially crafted pdf file can cause a buffe | Oct 28, 2016 | 7.8 | 22 | NO | NO |
CVE-2016-8715HIGH An exploitable heap corruption vulnerability exists in the loadTrailer functionality of Iceni Argus version 6.6.05. A specially crafted PDF file can cause a heap corruption resulti | Feb 28, 2017 | 7.8 | 20 | NO | NO |
CVE-2016-8389HIGH An exploitable integer-overflow vulnerability exists within Iceni Argus. When it attempts to convert a malformed PDF to XML, it will attempt to convert each character from a font i | Feb 28, 2017 | 7.8 | 20 | NO | NO |
CVE-2016-8388HIGH An exploitable arbitrary heap-overwrite vulnerability exists within Iceni Argus. When it attempts to convert a malformed PDF to XML, it will explicitly trust an index within the sp | Feb 28, 2017 | 7.8 | 20 | NO | NO |
CVE-2016-8385HIGH An exploitable uninitialized variable vulnerability which leads to a stack-based buffer overflow exists in Iceni Argus. When it attempts to convert a malformed PDF to XML a stack v | Feb 27, 2017 | 7.8 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Argus
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.6.05 | 2 | 7.8 | 1.5% | 0 | 0 |
| 6.6.04 | 7 | 7.8 | 2.1% | 0 | 0 |