Linux Desktop
Vendor:
First CVE: May 2, 2005 · Active for 21 years
12
Total CVEs
More Total CVEs than 90% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Linux Desktop over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Nov 4, 2009
6,107 days ago
CVE Severity & Scoring
Linux Desktop12 CVEs
25%
17%
58%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local3 (25.0%)
Network0 (0.0%)
Unknown9 (75.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (16.7%)
High1 (8.3%)
Unknown9 (75.0%)
User Interaction
None3 (25.0%)
Unknown9 (75.0%)
Required0 (0.0%)
Privileges Required
Low3 (25.0%)
High0 (0.0%)
None0 (0.0%)
Unknown9 (75.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3547HIGH Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privi | Nov 4, 2009 | 7.0 | 36 | NO | YES |
CVE-2006-0736HIGH Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary | Feb 27, 2006 | 10.0 | 27 | NO | NO |
CVE-2008-5021HIGH nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial | Nov 13, 2008 | 9.3 | 25 | NO | NO |
CVE-2008-2812HIGH The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vec | Jul 9, 2008 | 7.8 | 22 | NO | NO |
CVE-2005-1040HIGH Multiple unknown vulnerabilities in netapplet in Novell Linux Desktop 9 allow local users to gain root privileges, related to "User input [being] passed to network scripts without | May 2, 2005 | 7.2 | 20 | NO | NO |
CVE-2007-6716MEDIUM fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as de | Sep 4, 2008 | 5.5 | 19 | NO | NO |
CVE-2009-2848MEDIUM The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial o | Aug 18, 2009 | 5.9 | 18 | NO | NO |
CVE-2008-4636HIGH yast2-backup 2.14.2 through 2.16.6 on SUSE Linux and Novell Linux allows local users to gain privileges via shell metacharacters in filenames used by the backup process. | Nov 27, 2008 | 7.2 | 18 | NO | NO |
CVE-2005-1763HIGH Buffer overflow in ptrace in the Linux Kernel for 64-bit architectures allows local users to write bytes into kernel memory. | Jun 9, 2005 | 7.2 | 18 | NO | NO |
Linux kernel 2.6 and 2.4 on the IA64 architecture allows local users to cause a denial of service (kernel crash) via ptrace and the restore_sigcontext function. | Aug 5, 2005 | 2.1 | 11 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
8.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Linux Desktop
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9 | 11 | 6.0 | 1.7% | 0 | 1 |