Windriver
Vendor:
First CVE: Sep 11, 2017 · Active for 8 years
20
Total CVEs
More Total CVEs than 94% of tracked products
6.7
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Windriver over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 11, 2017
8 years ago
Most Recent CVE
Jul 2, 2024
754 days ago
CVE Severity & Scoring
Windriver20 CVEs
55%
45%
All CVEs352,719 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local20 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None18 (90.0%)
Unknown0 (0.0%)
Required2 (10.0%)
Privileges Required
Low18 (90.0%)
High0 (0.0%)
None2 (10.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-5189HIGH Race condition in Jungo Windriver 12.5.1 allows local users to cause a denial of service (buffer overflow) or gain system privileges by flipping pool buffer size, aka a "double fet | Jan 11, 2018 | 7.8 | 36 | NO | YES |
CVE-2017-14344HIGH This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to execute low-privileged code on | Sep 12, 2017 | 7.8 | 35 | NO | YES |
CVE-2017-14153HIGH This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to execute low-privileged code on | Sep 11, 2017 | 7.8 | 34 | NO | YES |
CVE-2017-14075HIGH This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to execute low-privileged code on | Sep 11, 2017 | 7.8 | 33 | NO | YES |
CVE-2024-26314HIGH Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and execute arbitrary code. | Jul 2, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-25088HIGH Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code. | Jul 2, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-22106HIGH Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cause a Denial of Service (DoS). | Jul 2, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-51776HIGH Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code. | Jul 2, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-25086HIGH Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code. | Jul 2, 2024 | 7.8 | 20 | NO | NO |
CVE-2018-8821MEDIUM windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a crafted .exe file. | Mar 20, 2018 | 5.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
20.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Windriver
Top CWEs
Versions
No cataloged versions.