Munin

Vendor:

First CVE: Aug 26, 2012 · Active for 13 years

9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Munin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 26, 2012
13 years ago
Most Recent CVE
Feb 22, 2017
3,441 days ago

CVE Severity & Scoring

Munin9 CVEs
All CVEs352,713 CVEs
LowMediumHigh
Attack Vector
Local1 (11.1%)
Network0 (0.0%)
Unknown8 (88.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (11.1%)
High0 (0.0%)
Unknown8 (88.9%)
User Interaction
None1 (11.1%)
Unknown8 (88.9%)
Required0 (0.0%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (88.9%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
cgi-bin/munin-cgi-graph in Munin 2.x writes data to a log file without sanitizing non-printable characters, which might allow user-assisted remote attackers to inject terminal emul
Aug 26, 20126.833NOYES
munin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files in arbitrary directories via t
Nov 21, 20129.328NONO
Munin before 2.0.6 stores plugin state files that run as root in the same group-writable directory as non-root plugins, which allows local users to execute arbitrary code by replac
Nov 21, 20127.224NONO
Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www
Feb 22, 20175.521NONO
munin-cgi-graph for Munin 2.0 rc4 does not delete temporary files, which allows remote attackers to cause a denial of service (disk consumption) via many requests to an image with
Aug 26, 20125.018NONO
munin-cgi-graph in Munin 2.0 rc4 allows remote attackers to cause a denial of service (disk or memory consumption) via many image requests with large values in the (1) size_x or (2
Aug 26, 20125.018NONO
The get_group_tree function in lib/Munin/Master/HTMLConfig.pm in Munin before 2.0.18 allows remote nodes to cause a denial of service (infinite loop and memory consumption in the m
Dec 13, 20135.015NONO
Munin::Master::Node in Munin before 2.0.18 allows remote attackers to cause a denial of service (abort data collection for node) via a plugin that uses "multigraph" as a multigraph
Dec 13, 20134.314NONO
The qmailscan plugin for Munin 1.4.5 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
Aug 26, 20121.213NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Munin

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.116.85.1%01
2.0-rc728.31.5%00
2.0-rc628.31.5%00
2.0-rc528.31.5%00
2.0-rc428.31.5%00
2.0_rc425.02.0%00
2.0-rc328.31.5%00
2.0-rc228.31.5%00
2.0-rc128.31.5%00
2.0-beta728.31.5%00
2.0-beta628.31.5%00
2.0-beta528.31.5%00
2.0-beta428.31.5%00
2.0-beta328.31.5%00
2.0-beta228.31.5%00
2.0-beta128.31.5%00
2.0.924.72.2%00
2.0.824.72.2%00
2.0.724.72.2%00
2.0.624.72.2%00