Bootstrap Os

Vendor:

First CVE: Oct 21, 2019 · Active for 6 years

56
Total CVEs
More Total CVEs than 98% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
5.4%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Bootstrap Os over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 21, 2019
6 years ago
Most Recent CVE
Apr 15, 2025
465 days ago

CVE Severity & Scoring

Bootstrap Os56 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local16 (28.6%)
Network40 (71.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (62.5%)
High21 (37.5%)
Unknown0 (0.0%)
User Interaction
None44 (78.6%)
Unknown0 (0.0%)
Required12 (21.4%)
Privileges Required
Low14 (25.0%)
High3 (5.4%)
None39 (69.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (56 CVEs).

56 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Defau
Mar 10, 20259.899YESYES
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to us
Oct 3, 20237.898YESYES
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth
Jul 1, 20248.189NOYES
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the
Mar 3, 20227.879YESYES
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to
Jun 21, 20227.376NONO
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-
Feb 14, 20247.572NONO
Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal
Sep 3, 20247.562NONO
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is
Dec 17, 20249.858NONO
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts t
Mar 27, 20248.646NONO
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number o
Jul 7, 20226.538NONO

Exploit Exposure

Signals from CVEs in this product scope (56 CVEs).

CISA KEV
3 CVEs
5.4% of CVEs· 97th percentile
Metasploit
3 CVEs
5.4% of CVEs· 97th percentile
Nuclei
2 CVEs
3.6% of CVEs· 97th percentile
ExploitDB
3 CVEs
5.4% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (56 CVEs).

Media Mentions

Signals from CVEs in this product scope (56 CVEs).

Top CNAs Publishing CVEs For Bootstrap Os

Top CWEs

Versions

No cataloged versions.