E Series Performance Analyzer

Vendor:

First CVE: Jul 1, 2019 · Active for 7 years

61
Total CVEs
More Total CVEs than 99% of tracked products
15.3
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 29% of tracked products
1.6%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact E Series Performance Analyzer over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 1, 2019
7 years ago
Most Recent CVE
Dec 7, 2022
1,328 days ago

CVE Severity & Scoring

E Series Performance Analyzer61 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local3 (4.9%)
Network58 (95.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (54.1%)
High28 (45.9%)
Unknown0 (0.0%)
User Interaction
None50 (82.0%)
Unknown0 (0.0%)
Required11 (18.0%)
Privileges Required
Low7 (11.5%)
High1 (1.6%)
None53 (86.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (61 CVEs).

61 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows
Jul 17, 20197.893YESYES
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP re
Jun 3, 20208.290NOYES
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources withi
Apr 1, 20215.386NOYES
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configurat
Mar 18, 20217.579NOYES
Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-sit
Jul 15, 20228.765NONO
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This
Mar 3, 20217.565NONO
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms
Mar 25, 20215.957NONO
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
Apr 1, 20217.554NONO
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect hand
Apr 21, 20207.551NONO
Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate
Dec 14, 20217.544NONO

Exploit Exposure

Signals from CVEs in this product scope (61 CVEs).

CISA KEV
1 CVE
1.6% of CVEs· 98th percentile
Metasploit
2 CVEs
3.3% of CVEs· 97th percentile
Nuclei
4 CVEs
6.6% of CVEs· 97th percentile
ExploitDB
3 CVEs
4.9% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (61 CVEs).

Media Mentions

Signals from CVEs in this product scope (61 CVEs).

Top CNAs Publishing CVEs For E Series Performance Analyzer

Top CWEs

Versions

No cataloged versions.