Mgetty
Vendor:
First CVE: Aug 18, 2003 · Active for 22 years
8
Total CVEs
More Total CVEs than 87% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mgetty over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 18, 2003
22 years ago
Most Recent CVE
Jul 24, 2019
2,560 days ago
CVE Severity & Scoring
Mgetty8 CVEs
38%
63%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local8 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (75.0%)
Unknown0 (0.0%)
Required2 (25.0%)
Privileges Required
Low6 (75.0%)
High0 (0.0%)
None2 (25.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16744HIGH An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized. It could allow for command injection if untrusted input ca | Sep 13, 2018 | 7.8 | 26 | NO | NO |
CVE-2018-16745HIGH An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized. It could allow a buffer overflow if long untrusted input c | Sep 13, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-16743HIGH An issue was discovered in mgetty before 1.2.1. In contrib/next-login/login.c, the command-line parameter username is passed unsanitized to strcpy(), which can cause a stack-based | Sep 13, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-16742HIGH An issue was discovered in mgetty before 1.2.1. In contrib/scrts.c, a stack-based buffer overflow can be triggered via a command-line parameter. | Sep 13, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-16741HIGH An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanitize shell metacharacters to prevent command injection. It is | Sep 13, 2018 | 7.8 | 25 | NO | NO |
CVE-2019-1010190MEDIUM mgetty prior to 1.2.1 is affected by: out-of-bounds read. The impact is: DoS, the program may crash if the memory is not mapped. The component is: putwhitespan() in g3/pbm2g3.c. Th | Jul 24, 2019 | 5.5 | 20 | NO | NO |
CVE-2019-1010189MEDIUM mgetty prior to version 1.2.1 is affected by: Infinite Loop. The impact is: DoS, the program does never terminates. The component is: g3/g32pbm.c. The attack vector is: Local, the | Jul 24, 2019 | 5.5 | 19 | NO | NO |
CVE-2003-0517MEDIUM faxrunqd.in in mgetty 1.1.28 and earlier allows local users to overwrite files via a symlink attack on JOB files. | Aug 18, 2003 | 5.5 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Mgetty
Top CWEs
Versions
No cataloged versions.