Element Software

Vendor:

First CVE: Aug 8, 2017 · Active for 8 years

100
Total CVEs
More Total CVEs than 99% of tracked products
12.5
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Element Software over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 8, 2017
8 years ago
Most Recent CVE
Feb 5, 2025
535 days ago

CVE Severity & Scoring

Element Software100 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local21 (21.0%)
Network76 (76.0%)
Unknown0 (0.0%)
Physical2 (2.0%)
Adjacent Network1 (1.0%)
Attack Complexity
Low63 (63.0%)
High37 (37.0%)
Unknown0 (0.0%)
User Interaction
None67 (67.0%)
Unknown0 (0.0%)
Required33 (33.0%)
Privileges Required
Low19 (19.0%)
High3 (3.0%)
None78 (78.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (100 CVEs).

100 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to
Jun 21, 20227.376NONO
The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd inst
Mar 6, 20187.551NOYES
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for ex
Jan 31, 20196.844NOYES
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number o
Jul 7, 20226.539NONO
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled
Jun 26, 20189.839NONO
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-aft
Sep 19, 20187.837NOYES
Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a respon
Mar 8, 20189.836NONO
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to r
Jan 28, 20198.135NONO
An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to retu
Feb 1, 20189.833NONO
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead
Apr 10, 20199.832NONO

Exploit Exposure

Signals from CVEs in this product scope (100 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
5.0% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (100 CVEs).

Media Mentions

Signals from CVEs in this product scope (100 CVEs).

Top CNAs Publishing CVEs For Element Software

Top CWEs

Versions

No cataloged versions.