Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nongnu

First CVE: Jun 14, 2007Active for: 19 yearsTotal CVEs: 8

Nongnu maintains a small portfolio of diverse open-source utilities and libraries spanning version control, system information, authentication, and notification components, many of which occupy specialized infrastructure and development roles. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, while the recurring weakness classes—memory-buffer issues, authentication flaws, and cross-site scripting in web-facing components—reflect the varied attack surfaces and legacy maturity of projects with different governance and update cadences. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nongnu over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 14, 2007
19 years ago
Most Recent CVE
Apr 13, 2023
1,198 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-17455CRITICAL
Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-bas
Oct 10, 20199.831NONO
CVE-2018-1000637HIGH
zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can result in Potential denial of service or arbitrary code execution. This attack ap
Aug 20, 20187.825NONO
CVE-2023-30630HIGH
Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. NOTE: Some third pa
Apr 13, 20237.123NONO
CVE-2010-3846MEDIUM
Array index error in the apply_rcs_change function in rcs.c in CVS 1.11.23 allows local users to gain privileges via an RCS file containing crafted delta fragment changes that trig
Nov 5, 20106.922NONO
CVE-2007-3209HIGH
Mail Notification 4.0, when WITH_SSL is set to 0 at compile time, uses unencrypted connections for accounts configured with SSL/TLS, which allows remote attackers to obtain sensiti
Jun 14, 20077.820NONO
CVE-2014-2886MEDIUM
GKSu 2.0.2, when sudo-mode is not enabled, uses " (double quote) characters in a gksu-run-helper argument, which allows attackers to execute arbitrary commands in certain situation
Sep 18, 20146.818NONO
CVE-2013-7322MEDIUM
usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly handle lines containing an invalid one-time-password (OTP) type and a user name in /etc/users.oath, which caus
Mar 9, 20144.918NONO
CVE-2009-0359LOW
Multiple cross-site scripting (XSS) vulnerabilities in Samizdat before 0.6.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) message title or (2
Feb 17, 20093.513NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
13%
38%
38%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (25.0%)
Network1 (12.5%)
Unknown5 (62.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (37.5%)
High0 (0.0%)
Unknown5 (62.5%)
User Interaction
None2 (25.0%)
Unknown5 (62.5%)
Required1 (12.5%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None2 (25.0%)
Unknown5 (62.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nongnu.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nongnu — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nongnu's Products

View all 2 CNAs →

Top CWEs