Libevent
Vendor:
First CVE: Aug 24, 2015 · Active for 10 years
5
Total CVEs
More Total CVEs than 77% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 69% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Libevent over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 24, 2015
10 years ago
Most Recent CVE
Mar 15, 2017
3,417 days ago
CVE Severity & Scoring
Libevent5 CVEs
80%
20%
All CVEs352,101 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network3 (60.0%)
Unknown2 (40.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (60.0%)
High0 (0.0%)
Unknown2 (40.0%)
User Interaction
None3 (60.0%)
Unknown2 (40.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (60.0%)
Unknown2 (40.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10195CRITICAL The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an | Mar 15, 2017 | 9.8 | 28 | NO | NO |
CVE-2016-10197HIGH The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty hostname. | Mar 15, 2017 | 7.5 | 27 | NO | NO |
CVE-2016-10196HIGH Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) | Mar 15, 2017 | 7.5 | 27 | NO | NO |
CVE-2014-6272HIGH Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial | Aug 24, 2015 | 7.5 | 26 | NO | NO |
CVE-2015-6525HIGH Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibl | Aug 24, 2015 | 7.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Libevent
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.1.4 | 2 | 7.5 | 3.5% | 0 | 0 |
| 2.1.3 | 2 | 7.5 | 3.5% | 0 | 0 |
| 2.1.2 | 2 | 7.5 | 3.5% | 0 | 0 |
| 2.1.1 | 2 | 7.5 | 3.5% | 0 | 0 |
| 2.0.9 | 2 | 7.5 | 3.5% | 0 | 0 |
| 2.0.8 | 2 | 7.5 | 3.5% | 0 | 0 |
| 2.0.7 | 2 | 7.5 | 3.5% | 0 | 0 |
| 2.0.6 | 2 | 7.5 | 3.5% | 0 | 0 |
| 2.0.5 | 2 | 7.5 | 3.5% | 0 | 0 |
| 2.0.4 | 2 | 7.5 | 3.5% | 0 | 0 |
| 2.0.3 | 2 | 7.5 | 3.5% | 0 | 0 |
| 2.0.21 | 2 | 7.5 | 3.5% | 0 | 0 |
| 2.0.20 | 2 | 7.5 | 3.5% | 0 | 0 |
| 2.0.2 | 2 | 7.5 | 3.5% | 0 | 0 |
| 2.0.19 | 2 | 7.5 | 3.5% | 0 | 0 |
| 2.0.18 | 2 | 7.5 | 3.5% | 0 | 0 |
| 2.0.17 | 2 | 7.5 | 3.5% | 0 | 0 |
| 2.0.16 | 2 | 7.5 | 3.5% | 0 | 0 |
| 2.0.15 | 2 | 7.5 | 3.5% | 0 | 0 |
| 2.0.14 | 2 | 7.5 | 3.5% | 0 | 0 |