Windows 95

Vendor:

First CVE: Jan 1, 1997 · Active for 29 years

57
Total CVEs
More Total CVEs than 98% of tracked products
5.7
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Windows 95 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 1997
29 years ago
Most Recent CVE
Feb 6, 2009
6,377 days ago

CVE Severity & Scoring

Windows 9557 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network1 (1.8%)
Unknown56 (98.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (1.8%)
High0 (0.0%)
Unknown56 (98.2%)
User Interaction
None0 (0.0%)
Unknown56 (98.2%)
Required1 (1.8%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (1.8%)
Unknown56 (98.2%)

Top CVEs

Signals from CVEs in this product scope (57 CVEs).

57 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Land IP denial of service.
Dec 1, 19975.079NOYES
Buffer overflow in War FTP allows remote execution of commands.
Feb 1, 19987.577NOYES
File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access
Dec 19, 20006.454NOYES
Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragme
May 19, 20007.849NOYES
Denial of service in various Windows systems via malformed, fragmented IGMP packets.
Jul 3, 19997.844NOYES
Teardrop IP denial of service.
Dec 16, 19975.043NOYES
Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary
Mar 8, 20027.542NONO
Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certain GIF file, as demonstrated by Art.gif.
Jul 24, 20077.138NOYES
PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter.
May 17, 200710.036NOYES
Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP
Jan 9, 20015.036NONO

Exploit Exposure

Signals from CVEs in this product scope (57 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.8% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
22 CVEs
38.6% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (57 CVEs).

Media Mentions

Signals from CVEs in this product scope (57 CVEs).

Top CNAs Publishing CVEs For Windows 95

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
0b27.511.1%01
0a36.710.4%01
0.0a15.035.7%01