Snapprotect
Vendor:
First CVE: Sep 21, 2016 · Active for 9 years
18
Total CVEs
More Total CVEs than 93% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
11.1%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Snapprotect over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2016
9 years ago
Most Recent CVE
May 17, 2019
2,625 days ago
CVE Severity & Scoring
Snapprotect18 CVEs
28%
67%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local9 (50.0%)
Network7 (38.9%)
Unknown0 (0.0%)
Physical1 (5.6%)
Adjacent Network1 (5.6%)
Attack Complexity
Low11 (61.1%)
High7 (38.9%)
Unknown0 (0.0%)
User Interaction
None17 (94.4%)
Unknown0 (0.0%)
Required1 (5.6%)
Privileges Required
Low10 (55.6%)
High0 (0.0%)
None8 (44.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-5195HIGH Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature | Nov 10, 2016 | 7.0 | 95 | YES | YES |
CVE-2018-14634HIGH An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use thi | Sep 25, 2018 | 7.8 | 81 | YES | YES |
CVE-2019-3844HIGH It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by | Apr 26, 2019 | 7.8 | 36 | NO | YES |
CVE-2019-3843HIGH It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the s | Apr 26, 2019 | 7.8 | 36 | NO | YES |
CVE-2019-10125CRITICAL An issue was discovered in aio_poll() in fs/aio.c in the Linux kernel through 5.0.4. A file may be released by aio_poll_wake() if an expected event is triggered immediately (e.g., | Mar 27, 2019 | 9.8 | 34 | NO | NO |
CVE-2019-1559MEDIUM If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently | Feb 27, 2019 | 5.9 | 30 | NO | NO |
CVE-2019-11815HIGH An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace clea | May 8, 2019 | 8.1 | 29 | NO | NO |
CVE-2019-9162HIGH In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ASN.1 length checks (aka an array index error), making out-o | Feb 25, 2019 | 7.8 | 29 | NO | YES |
CVE-2018-20836HIGH An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a us | May 7, 2019 | 8.1 | 28 | NO | NO |
CVE-2019-3900HIGH An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one | Apr 25, 2019 | 7.7 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
2 CVEs
11.1% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
27.8% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Snapprotect
Top CWEs
Versions
No cataloged versions.