Klibc
Vendor:
First CVE: Nov 14, 2019 · Active for 6 years
5
Total CVEs
More Total CVEs than 77% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
9.3
Avg CVSS
Higher Avg CVSS than 87% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Klibc over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 14, 2019
6 years ago
Most Recent CVE
Apr 30, 2021
1,911 days ago
CVE Severity & Scoring
Klibc5 CVEs
20%
80%
All CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-1930CRITICAL In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHC | Nov 14, 2019 | 9.8 | 51 | NO | YES |
CVE-2021-31872CRITICAL An issue was discovered in klibc before 2.0.9. Multiple possible integer overflows in the cpio command on 32-bit systems may result in a buffer overflow or other security impact. | Apr 30, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-31873CRITICAL An issue was discovered in klibc before 2.0.9. Additions in the malloc() function may result in an integer overflow and a subsequent heap buffer overflow. | Apr 30, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-31870CRITICAL An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in an integer overflow and a subsequent heap buffer overflow. | Apr 30, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-31871HIGH An issue was discovered in klibc before 2.0.9. An integer overflow in the cpio command may result in a NULL pointer dereference on 64-bit systems. | Apr 30, 2021 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
20.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Klibc
Top CWEs
Versions
No cataloged versions.