Immunix maintains a narrowly focused product portfolio centered on security-hardening technologies, notably StackGuard, which has achieved prominence in the landscape despite modest disclosure volume. The vendor's vulnerabilities recur around implementation-level weaknesses such as off-by-one errors and parsing ambiguities that are characteristic of low-level systems software, and the exposure frequently acquires public exploit code. Defenders tracking this vendor should treat the limited product surface as a concentrated dependency point—flaws in core hardening mechanisms warrant close attention even when disclosed infrequently. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Immunix over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0083CRITICAL Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges. | Mar 15, 2002 | 9.8 | 48 | NO | YES |
CVE-2000-0844HIGH Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via fun | Nov 14, 2000 | 10.0 | 44 | NO | YES |
CVE-2000-1134HIGH Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here docu | Jan 9, 2001 | 7.2 | 29 | NO | YES |
CVE-2000-1095HIGH modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters. | Jan 9, 2001 | 7.2 | 27 | NO | YES |
CVE-2001-0641MEDIUM Buffer overflow in man program in various distributions of Linux allows local user to execute arbitrary code as group man via a long -S option. | Sep 20, 2001 | 4.6 | 26 | NO | YES |
CVE-2002-1565HIGH Buffer overflow in url_filename function for wget 1.8.1 allows attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long URL. | Jun 16, 2003 | 7.5 | 25 | NO | NO |
CVE-2000-1208HIGH Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses fo | Aug 12, 2002 | 7.2 | 24 | NO | NO |
CVE-2001-0473HIGH Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands. | Jun 27, 2001 | 7.5 | 24 | NO | NO |
CVE-2000-0963HIGH Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS. | Dec 19, 2000 | 7.2 | 23 | NO | NO |
CVE-2001-1030HIGH Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows | Jul 18, 2001 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Immunix.
Media articles that mention a CVE ID that affects a product developed by Immunix — matched by CVE ID, not by vendor name.