The OpenGroup maintains stewardship of widely adopted Unix standards and the Common Desktop Environment, which have been incorporated into numerous operating systems and server distributions across decades of deployment. Despite a narrow product list, the vendor's specifications and reference implementations underpin a substantial installed base, particularly in enterprise and legacy systems where longevity creates persistent exposure windows. Vulnerabilities affecting the vendor span memory-safety issues—including classic buffer overflows, out-of-bounds writes, and unbounded resource allocation—as well as input-validation weaknesses that recur across the X Window System and desktop environment components. The exposure exhibits a moderate tendency toward serious severity outcomes and a corresponding moderate frequency of confirmed in-the-wild exploitation and public exploit availability, reflecting both the attack surface presented by long-lived systems and the historical maturity of exploitation techniques against these foundational technologies. Defenders should inventory systems claiming Unix conformance and Common Desktop Environment components, particularly in air-gapped or legacy environments where patching cycles are infrequent; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opengroup over time
Signals from CVEs in this vendor scope (57 CVEs).
57 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-2462CRITICAL Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote att | Dec 7, 2011 | 9.8 | 98 | YES | YES |
CVE-2022-30333HIGH RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_ke | May 9, 2022 | 7.5 | 97 | YES | YES |
CVE-2013-0625CRITICAL Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vect | Jan 9, 2013 | 9.8 | 97 | YES | YES |
CVE-2013-0629HIGH Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vectors, as exploited in the wild i | Jan 9, 2013 | 7.5 | 92 | YES | YES |
CVE-2013-0631HIGH Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in January 2013. | Jan 9, 2013 | 7.5 | 89 | YES | NO |
CVE-2001-0803HIGH Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands. | Dec 6, 2001 | 10.0 | 85 | NO | YES |
CVE-2014-2648HIGH Unspecified vulnerability in HP Operations Manager 9.10 and 9.11 on UNIX allows remote attackers to execute arbitrary code via unknown vectors. | Oct 10, 2014 | 10.0 | 34 | NO | NO |
CVE-2025-36372MEDIUM IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information to an authenticated user fro | Jun 30, 2026 | 6.5 | 29 | NO | NO |
CVE-2011-4374HIGH Integer overflow in Adobe Reader 9.x before 9.4.6 on Linux allows attackers to execute arbitrary code via unspecified vectors. | Jan 19, 2012 | 9.3 | 29 | NO | NO |
CVE-2004-0368HIGH Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet. | May 4, 2004 | 10.0 | 29 | NO | NO |
Signals from CVEs in this vendor scope (57 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opengroup.
Media articles that mention a CVE ID that affects a product developed by Opengroup — matched by CVE ID, not by vendor name.