Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Next

First CVE: Oct 3, 1990Active for: 36 yearsTotal CVEs: 10
55.1
VTI Score
TOP TARGET

Next's vulnerability profile centers on a narrow legacy product line spanning operating systems and development environments including NeXTSTEP, OpenStep, and related platforms. The recurring exposure involves memory-safety issues, particularly buffer overflows and input-validation weaknesses characteristic of systems software from that era, and the associated disclosures have frequently acquired public exploit tooling. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Next over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 3, 1990
35 years ago
Most Recent CVE
Oct 3, 2006
7,234 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-1999-0046HIGH
Buffer overflow of rlogin program using TERM environmental variable.
Feb 6, 199710.067NOYES
CVE-1999-0032HIGH
Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.
Oct 25, 19967.229NOYES
CVE-2006-4392HIGH
The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, allows local users to gain privileges via a parent process tha
Oct 3, 20067.227NOYES
CVE-1999-1193HIGH
The "me" user in NeXT NeXTstep 2.1 and earlier has wheel group privileges, which could allow the me user to use the su command to become root.
May 14, 199110.025NONO
CVE-1999-0956HIGH
The NeXT NetInfo _writers property allows local users to gain root privileges or conduct a denial of service.
Sep 19, 19977.218NONO
CVE-1999-1198HIGH
BuildDisk program on NeXT systems before 2.0 does not prompt users for the root password, which allows local users to gain root privileges.
Oct 3, 19907.218NONO
CVE-1999-1391HIGH
Vulnerability in NeXT 1.0a and 1.0 with publicly accessible printers allows local users to gain privileges via a combination of the npd program and weak directory permissions.
Oct 3, 19907.218NONO
CVE-1999-1392HIGH
Vulnerability in restore0.9 installation script in NeXT 1.0a and 1.0 allows local users to gain root privileges.
Oct 3, 19907.218NONO
CVE-1999-1468MEDIUM
rdist in various UNIX systems uses popen to execute sendmail, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable.
Oct 22, 19916.217NONO
CVE-1999-0078LOW
pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.
Apr 18, 19961.913NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
10%
10%
80%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown10 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown10 (100.0%)
User Interaction
None0 (0.0%)
Unknown10 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown10 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
30.0% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Next.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Next — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Next's Products

View all 1 CNAs →

Top CWEs