Linux
Vendor:
First CVE: Oct 12, 2005 · Active for 20 years
6
Total CVEs
More Total CVEs than 80% of tracked products
1.2
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Linux over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 12, 2005
20 years ago
Most Recent CVE
May 20, 2011
5,544 days ago
CVE Severity & Scoring
Linux6 CVEs
17%
50%
33%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown6 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown6 (100.0%)
User Interaction
None0 (0.0%)
Unknown6 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown6 (100.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-2162HIGH Multiple unspecified vulnerabilities in FFmpeg 0.4.x through 0.6.x, as used in MPlayer 1.0 and other products, in Mandriva Linux 2009.0, 2010.0, and 2010.1; Corporate Server 4.0 (a | May 20, 2011 | 10.0 | 31 | NO | NO |
CVE-2010-2529MEDIUM Unspecified vulnerability in ping.c in iputils 20020927, 20070202, 20071127, and 20100214 on Mandriva Linux allows remote attackers to cause a denial of service (hang) via a crafte | Jul 28, 2010 | 5.0 | 20 | NO | NO |
CVE-2009-0912HIGH perl-MDK-Common 1.1.11 and 1.1.24, 1.2.9 through 1.2.14, and possibly other versions, in Mandriva Linux does not properly handle strings when writing them to configuration files, w | Mar 16, 2009 | 7.2 | 18 | NO | NO |
CVE-2009-0032MEDIUM CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink | Jan 27, 2009 | 6.9 | 18 | NO | NO |
CVE-2007-3741MEDIUM The (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user-assisted remote attackers to cause a denial of service (crash or memory consumption) via crafted im | Aug 27, 2007 | 4.3 | 15 | NO | NO |
The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which preven | Oct 12, 2005 | 2.1 | 11 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Linux
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2010.1 | 1 | 10.0 | 2.3% | 0 | 0 |
| 2010.0 | 1 | 10.0 | 2.3% | 0 | 0 |
| 2009.0 | 2 | 8.1 | 1.0% | 0 | 0 |
| 2008.1 | 1 | 7.2 | 0.4% | 0 | 0 |
| 2008.0 | 1 | 7.2 | 0.4% | 0 | 0 |
| 2006.0 | 1 | 2.1 | 0.5% | 0 | 0 |
| 10.2 | 1 | 2.1 | 0.5% | 0 | 0 |
| 10.1 | 1 | 2.1 | 0.5% | 0 | 0 |