Mtr is a modestly represented network diagnostic utility that provides packet routing and connectivity path analysis functionality across Unix and Linux systems. The limited vulnerability signal reflects the utility's narrow scope and command-line interface; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mtr over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-49809HIGH mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environment variable. NOTE: mtr on macOS may often have Sudo rules, | Jul 4, 2025 | 7.8 | 22 | NO | NO |
CVE-2004-1224MEDIUM Off-by-one error in the mtr_curses_keyaction function for mtr 0.55 through 0.65 allows local users to hijack raw sockets, as demonstrated using the "s" keybinding, which leaves a b | Jan 10, 2005 | 4.6 | 18 | NO | NO |
Buffer overflow in mtr 0.46 and earlier, when installed setuid root, allows local users to access a raw socket via a long MTR_OPTIONS environment variable. | Aug 12, 2002 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mtr.
Media articles that mention a CVE ID that affects a product developed by Mtr — matched by CVE ID, not by vendor name.