Munin
Vendor:
First CVE: Aug 26, 2012 · Active for 13 years
9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Munin over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 26, 2012
13 years ago
Most Recent CVE
Feb 22, 2017
3,441 days ago
CVE Severity & Scoring
Munin9 CVEs
11%
67%
22%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (11.1%)
Network0 (0.0%)
Unknown8 (88.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (11.1%)
High0 (0.0%)
Unknown8 (88.9%)
User Interaction
None1 (11.1%)
Unknown8 (88.9%)
Required0 (0.0%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (88.9%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2104MEDIUM cgi-bin/munin-cgi-graph in Munin 2.x writes data to a log file without sanitizing non-printable characters, which might allow user-assisted remote attackers to inject terminal emul | Aug 26, 2012 | 6.8 | 33 | NO | YES |
CVE-2012-3513HIGH munin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files in arbitrary directories via t | Nov 21, 2012 | 9.3 | 28 | NO | NO |
CVE-2012-3512HIGH Munin before 2.0.6 stores plugin state files that run as root in the same group-writable directory as non-root plugins, which allows local users to execute arbitrary code by replac | Nov 21, 2012 | 7.2 | 24 | NO | NO |
CVE-2017-6188MEDIUM Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www | Feb 22, 2017 | 5.5 | 21 | NO | NO |
CVE-2012-4678MEDIUM munin-cgi-graph for Munin 2.0 rc4 does not delete temporary files, which allows remote attackers to cause a denial of service (disk consumption) via many requests to an image with | Aug 26, 2012 | 5.0 | 18 | NO | NO |
CVE-2012-2147MEDIUM munin-cgi-graph in Munin 2.0 rc4 allows remote attackers to cause a denial of service (disk or memory consumption) via many image requests with large values in the (1) size_x or (2 | Aug 26, 2012 | 5.0 | 18 | NO | NO |
CVE-2013-6048MEDIUM The get_group_tree function in lib/Munin/Master/HTMLConfig.pm in Munin before 2.0.18 allows remote nodes to cause a denial of service (infinite loop and memory consumption in the m | Dec 13, 2013 | 5.0 | 15 | NO | NO |
CVE-2013-6359MEDIUM Munin::Master::Node in Munin before 2.0.18 allows remote attackers to cause a denial of service (abort data collection for node) via a plugin that uses "multigraph" as a multigraph | Dec 13, 2013 | 4.3 | 14 | NO | NO |
The qmailscan plugin for Munin 1.4.5 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names. | Aug 26, 2012 | 1.2 | 13 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Munin
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.1 | 1 | 6.8 | 5.1% | 0 | 1 |
| 2.0-rc7 | 2 | 8.3 | 1.5% | 0 | 0 |
| 2.0-rc6 | 2 | 8.3 | 1.5% | 0 | 0 |
| 2.0-rc5 | 2 | 8.3 | 1.5% | 0 | 0 |
| 2.0-rc4 | 2 | 8.3 | 1.5% | 0 | 0 |
| 2.0_rc4 | 2 | 5.0 | 2.0% | 0 | 0 |
| 2.0-rc3 | 2 | 8.3 | 1.5% | 0 | 0 |
| 2.0-rc2 | 2 | 8.3 | 1.5% | 0 | 0 |
| 2.0-rc1 | 2 | 8.3 | 1.5% | 0 | 0 |
| 2.0-beta7 | 2 | 8.3 | 1.5% | 0 | 0 |
| 2.0-beta6 | 2 | 8.3 | 1.5% | 0 | 0 |
| 2.0-beta5 | 2 | 8.3 | 1.5% | 0 | 0 |
| 2.0-beta4 | 2 | 8.3 | 1.5% | 0 | 0 |
| 2.0-beta3 | 2 | 8.3 | 1.5% | 0 | 0 |
| 2.0-beta2 | 2 | 8.3 | 1.5% | 0 | 0 |
| 2.0-beta1 | 2 | 8.3 | 1.5% | 0 | 0 |
| 2.0.9 | 2 | 4.7 | 2.2% | 0 | 0 |
| 2.0.8 | 2 | 4.7 | 2.2% | 0 | 0 |
| 2.0.7 | 2 | 4.7 | 2.2% | 0 | 0 |
| 2.0.6 | 2 | 4.7 | 2.2% | 0 | 0 |