8700
Vendor:
First CVE: Nov 4, 2019 · Active for 6 years
16
Total CVEs
More Total CVEs than 92% of tracked products
3.2
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
6.3%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact 8700 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 4, 2019
6 years ago
Most Recent CVE
Jul 1, 2024
753 days ago
CVE Severity & Scoring
870016 CVEs
56%
44%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local12 (75.0%)
Network3 (18.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (6.3%)
Attack Complexity
Low11 (68.8%)
High5 (31.3%)
Unknown0 (0.0%)
User Interaction
None16 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low11 (68.8%)
High2 (12.5%)
None3 (18.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6387HIGH A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth | Jul 1, 2024 | 8.1 | 89 | NO | YES |
CVE-2021-22600HIGH A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgr | Jan 26, 2022 | 7.0 | 64 | YES | NO |
CVE-2020-8835HIGH In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads an | Apr 2, 2020 | 7.8 | 31 | NO | NO |
CVE-2020-29661HIGH A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf | Dec 9, 2020 | 7.8 | 28 | NO | NO |
CVE-2019-5108MEDIUM An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location | Dec 23, 2019 | 6.5 | 27 | NO | NO |
CVE-2022-30594HIGH The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag. | May 12, 2022 | 7.8 | 26 | NO | NO |
CVE-2019-18683HIGH An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users | Nov 4, 2019 | 7.0 | 24 | NO | NO |
CVE-2023-1077HIGH In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy e | Mar 27, 2023 | 7.0 | 22 | NO | NO |
CVE-2019-18282MEDIUM The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a | Jan 16, 2020 | 5.3 | 20 | NO | NO |
CVE-2019-20095MEDIUM mwifiex_tm_cmd in drivers/net/wireless/marvell/mwifiex/cfg80211.c in the Linux kernel before 5.1.6 has some error-handling cases that did not free allocated hostcmd memory, aka CID | Dec 30, 2019 | 5.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
1 CVE
6.2% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
6.2% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For 8700
Top CWEs
Versions
No cataloged versions.