500f
Vendor:
First CVE: Nov 28, 2020 · Active for 5 years
14
Total CVEs
More Total CVEs than 91% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
7.1%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact 500f over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 28, 2020
5 years ago
Most Recent CVE
Sep 3, 2024
689 days ago
CVE Severity & Scoring
500f14 CVEs
29%
64%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local5 (35.7%)
Network9 (64.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (50.0%)
High7 (50.0%)
Unknown0 (0.0%)
User Interaction
None13 (92.9%)
Unknown0 (0.0%)
Required1 (7.1%)
Privileges Required
Low5 (35.7%)
High0 (0.0%)
None9 (64.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6387HIGH A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth | Jul 1, 2024 | 8.1 | 89 | NO | YES |
CVE-2024-1086HIGH A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation.
The nft_verdict_init() function allows | Jan 31, 2024 | 7.8 | 79 | YES | NO |
CVE-2023-25136MEDIUM OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unaut | Feb 3, 2023 | 6.5 | 71 | NO | NO |
CVE-2022-0778HIGH The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsi | Mar 15, 2022 | 7.5 | 65 | NO | NO |
CVE-2024-6119HIGH Issue summary: Applications performing certificate name checks (e.g., TLS
clients checking server certificates) may attempt to read an invalid memory
address resulting in abnormal | Sep 3, 2024 | 7.5 | 62 | NO | NO |
CVE-2020-8625HIGH BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerabl | Feb 17, 2021 | 8.1 | 62 | NO | NO |
CVE-2021-4044HIGH Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate | Dec 14, 2021 | 7.5 | 44 | NO | NO |
CVE-2021-25215HIGH In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.1 | Apr 29, 2021 | 7.5 | 29 | NO | NO |
CVE-2021-26708HIGH A local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation are caused by wrong locking in net/vmw_vsock | Feb 5, 2021 | 7.0 | 24 | NO | NO |
CVE-2020-25668HIGH A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op. | May 26, 2021 | 7.0 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
1 CVE
7.1% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.1% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For 500f
Top CWEs
Versions
No cataloged versions.