Snapdrive
Vendor:
First CVE: Sep 21, 2016 · Active for 9 years
18
Total CVEs
More Total CVEs than 93% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Snapdrive over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2016
9 years ago
Most Recent CVE
May 3, 2022
1,543 days ago
CVE Severity & Scoring
Snapdrive18 CVEs
33%
50%
17%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (77.8%)
High4 (22.2%)
Unknown0 (0.0%)
User Interaction
None16 (88.9%)
Unknown0 (0.0%)
Required2 (11.1%)
Privileges Required
Low1 (5.6%)
High0 (0.0%)
None17 (94.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-8610HIGH A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection | Nov 13, 2017 | 7.5 | 39 | NO | NO |
CVE-2018-18312CRITICAL Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. | Dec 5, 2018 | 9.8 | 38 | NO | NO |
CVE-2018-18314CRITICAL Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations. | Dec 7, 2018 | 9.8 | 33 | NO | NO |
CVE-2018-18313CRITICAL Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory. | Dec 7, 2018 | 9.1 | 33 | NO | NO |
CVE-2021-3517HIGH There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application li | May 19, 2021 | 8.6 | 31 | NO | NO |
CVE-2019-1559MEDIUM If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently | Feb 27, 2019 | 5.9 | 30 | NO | NO |
CVE-2022-23308HIGH valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. | Feb 26, 2022 | 7.5 | 28 | NO | NO |
CVE-2021-3518HIGH There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-afte | May 18, 2021 | 8.8 | 28 | NO | NO |
CVE-2018-12015HIGH In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file con | Jun 7, 2018 | 7.5 | 28 | NO | NO |
CVE-2015-8960HIGH The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the a | Sep 21, 2016 | 8.1 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Snapdrive
Top CWEs
Versions
No cataloged versions.