Hci Bootstrap Os
Vendor:
First CVE: May 23, 2019 · Active for 7 years
27
Total CVEs
More Total CVEs than 96% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Hci Bootstrap Os over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 23, 2019
7 years ago
Most Recent CVE
May 6, 2024
812 days ago
CVE Severity & Scoring
Hci Bootstrap Os27 CVEs
44%
44%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local6 (22.2%)
Network20 (74.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (3.7%)
Attack Complexity
Low20 (74.1%)
High7 (25.9%)
Unknown0 (0.0%)
User Interaction
None25 (92.6%)
Unknown0 (0.0%)
Required2 (7.4%)
Privileges Required
Low8 (29.6%)
High1 (3.7%)
None18 (66.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28531CRITICAL ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9. | Mar 17, 2023 | 9.8 | 35 | NO | NO |
CVE-2020-8285HIGH curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing. | Dec 14, 2020 | 7.5 | 28 | NO | NO |
CVE-2022-27780HIGH The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it i | Jun 2, 2022 | 7.5 | 26 | NO | NO |
CVE-2022-27775HIGH An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it | Jun 2, 2022 | 7.5 | 26 | NO | NO |
CVE-2021-38202HIGH fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace eve | Aug 8, 2021 | 7.5 | 26 | NO | NO |
CVE-2021-38201HIGH net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_base slab-out-of-bounds access) by performing many NFS 4.2 REA | Aug 8, 2021 | 7.5 | 26 | NO | NO |
CVE-2021-38160HIGH In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buf | Aug 7, 2021 | 7.8 | 26 | NO | NO |
CVE-2020-8286HIGH curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. | Dec 14, 2020 | 7.5 | 26 | NO | NO |
CVE-2024-33599HIGH nscd: Stack-based buffer overflow in netgroup cache
If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted
by client requests then a subsequent client request for | May 6, 2024 | 8.1 | 25 | NO | NO |
CVE-2019-0201MEDIUM An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requ | May 23, 2019 | 5.9 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (27 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (27 CVEs).
Media Mentions
Signals from CVEs in this product scope (27 CVEs).
Top CNAs Publishing CVEs For Hci Bootstrap Os
Top CWEs
Versions
No cataloged versions.