Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Llvm

First CVE: Apr 23, 2014Active for: 12 yearsTotal CVEs: 9

LLVM is a modestly represented compiler infrastructure and toolchain project with a narrow product portfolio centered on the LLVM compiler framework and its Clang front-end, both widely embedded in development environments, operating systems, and language runtimes. Its vulnerability profile centers on memory-safety and file-handling weaknesses—out-of-bounds reads, buffer overflows, improper memory bounds checks, and link-following issues—that reflect the low-level nature of compiler optimization and code generation. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
5.1
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Llvm over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 23, 2014
12 years ago
Most Recent CVE
May 5, 2023
1,176 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-29939MEDIUM
llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::spirv::TargetEnv::TargetEnv(mlir::spirv::TargetEnvAttr).
May 5, 20235.520NONO
CVE-2023-29935MEDIUM
llvm-project commit a0138390 was discovered to contain an assertion failure at !replacements.count(op) && "operation was already replaced.
May 5, 20235.520NONO
CVE-2023-26924MEDIUM
LLVM a0dab4950 has a segmentation fault in mlir::outlineSingleBlockRegion. NOTE: third parties dispute this because the LLVM security policy excludes "Language front-ends ... for w
Mar 27, 20235.520NONO
CVE-2023-29941MEDIUM
llvm-project commit a0138390 was discovered to contain a segmentation fault via the component matchAndRewriteSortOp<mlir::sparse_tensor::SortOp>(mlir::sparse_tensor::SortOp.
May 5, 20235.519NONO
CVE-2023-29934MEDIUM
llvm-project commit 6c01b5c was discovered to contain a segmentation fault via the component mlir::Type::getDialect().
May 5, 20235.519NONO
CVE-2023-29933MEDIUM
llvm-project commit bd456297 was discovered to contain a segmentation fault via the component mlir::Block::getArgument.
May 5, 20235.519NONO
CVE-2023-29932MEDIUM
llvm-project commit fdbc55a5 was discovered to contain a segmentation fault via the component mlir::IROperand<mlir::OpOperand.
May 5, 20235.519NONO
CVE-2023-29942MEDIUM
llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::Type::isa<mlir::LLVM::LLVMVoidType.
May 5, 20235.516NONO
CVE-2014-2893LOW
The GetHTMLRunDir function in the scan-build utility in Clang 3.5 and earlier allows local users to obtain sensitive information or overwrite arbitrary files via a symlink attack o
Apr 23, 20141.911NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
11%
89%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMedium
Attack Vector
Local8 (88.9%)
Network0 (0.0%)
Unknown1 (11.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High0 (0.0%)
Unknown1 (11.1%)
User Interaction
None1 (11.1%)
Unknown1 (11.1%)
Required7 (77.8%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None7 (77.8%)
Unknown1 (11.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Llvm.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Llvm — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Llvm's Products

View all 1 CNAs →

Top CWEs