Iputils is a foundational network diagnostic and utilities package distributed across Unix and Linux systems, with a narrow but deeply embedded product scope. Its observed vulnerabilities center on integer overflow and wraparound conditions in command-line tools such as ping and traceroute that parse network traffic and system input. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iputils over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-47268MEDIUM ping in iputils before 20250602 allows a denial of service (application error or incorrect data collection) via a crafted ICMP Echo Reply packet, because of a signed 64-bit integer | May 5, 2025 | 6.5 | 21 | NO | NO |
CVE-2025-48964MEDIUM ping in iputils before 20250602 allows a denial of service (application error in adaptive ping mode or incorrect data collection) via a crafted ICMP Echo Reply packet, because a ze | Jul 22, 2025 | 6.5 | 20 | NO | NO |
CVE-2000-1213HIGH ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases | Oct 18, 2000 | 7.5 | 20 | NO | NO |
CVE-2000-1214MEDIUM Buffer overflows in the (1) outpack or (2) buf variables of ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, may allow l | Oct 18, 2000 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iputils.
Media articles that mention a CVE ID that affects a product developed by Iputils — matched by CVE ID, not by vendor name.