Niels Provos is known for a small set of widely embedded security and systems infrastructure tools, including the honeyd honeypot framework, libevent event-handling library, and systrace mandatory-access-control system, each of which serves a specialized role in defensive or systems-level deployments. The sparsity of disclosures and the NVD classification of observed weaknesses reflect the niche, low-surface-character of these tools; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Niels Provos over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-0343HIGH Niels Provos Systrace 1.6f and earlier on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 32-bit syscall with a syscall number that | Jan 29, 2009 | 7.2 | 27 | NO | YES |
CVE-2007-1030HIGH Niels Provos libevent 1.2 and 1.2a allows remote attackers to cause a denial of service (infinite loop) via a DNS response containing a label pointer that references its own offset | Feb 21, 2007 | 7.8 | 21 | NO | NO |
CVE-2006-4292MEDIUM Unspecified vulnerability in Niels Provos Honeyd before 1.5b allows remote attackers to cause a denial of service (application crash) via certain Address Resolution Protocol (ARP) | Aug 22, 2006 | 5.0 | 18 | NO | NO |
CVE-2006-0752MEDIUM Niels Provos Honeyd before 1.5 replies to certain illegal IP packet fragments that other IP stack implementations would drop, which allows remote attackers to identify IP addresses | Feb 18, 2006 | 5.0 | 15 | NO | NO |
CVE-2004-2095MEDIUM Honeyd before 0.8 replies to TCP packets with the SYN and RST flags set, which allows remote attackers to identify IP addresses that are being simulated by Honeyd. | Dec 31, 2004 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Niels Provos.
Media articles that mention a CVE ID that affects a product developed by Niels Provos — matched by CVE ID, not by vendor name.