Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Opengroup

First CVE: Jun 19, 2000Active for: 26 yearsTotal CVEs: 57
71.2
VTI Score
TOP TARGET

The OpenGroup maintains stewardship of widely adopted Unix standards and the Common Desktop Environment, which have been incorporated into numerous operating systems and server distributions across decades of deployment. Despite a narrow product list, the vendor's specifications and reference implementations underpin a substantial installed base, particularly in enterprise and legacy systems where longevity creates persistent exposure windows. Vulnerabilities affecting the vendor span memory-safety issues—including classic buffer overflows, out-of-bounds writes, and unbounded resource allocation—as well as input-validation weaknesses that recur across the X Window System and desktop environment components. The exposure exhibits a moderate tendency toward serious severity outcomes and a corresponding moderate frequency of confirmed in-the-wild exploitation and public exploit availability, reflecting both the attack surface presented by long-lived systems and the historical maturity of exploitation techniques against these foundational technologies. Defenders should inventory systems claiming Unix conformance and Common Desktop Environment components, particularly in air-gapped or legacy environments where patching cycles are infrequent; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
57
Total CVEs
More Total CVEs than 98% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
8.8%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Opengroup over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 19, 2000
26 years ago
Most Recent CVE
Jun 30, 2026
24 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (57 CVEs).

57 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2011-2462CRITICAL
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote att
Dec 7, 20119.898YESYES
CVE-2022-30333HIGH
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_ke
May 9, 20227.597YESYES
CVE-2013-0625CRITICAL
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vect
Jan 9, 20139.897YESYES
CVE-2013-0629HIGH
Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vectors, as exploited in the wild i
Jan 9, 20137.592YESYES
CVE-2013-0631HIGH
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in January 2013.
Jan 9, 20137.589YESNO
CVE-2001-0803HIGH
Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands.
Dec 6, 200110.085NOYES
CVE-2014-2648HIGH
Unspecified vulnerability in HP Operations Manager 9.10 and 9.11 on UNIX allows remote attackers to execute arbitrary code via unknown vectors.
Oct 10, 201410.034NONO
CVE-2025-36372MEDIUM
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information to an authenticated user fro
Jun 30, 20266.529NONO
CVE-2011-4374HIGH
Integer overflow in Adobe Reader 9.x before 9.4.6 on Linux allows attackers to execute arbitrary code via unspecified vectors.
Jan 19, 20129.329NONO
CVE-2004-0368HIGH
Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.
May 4, 200410.029NONO
View all 57 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products57 CVEs
26%
67%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local13 (22.8%)
Network34 (59.6%)
Unknown9 (15.8%)
Physical0 (0.0%)
Adjacent Network1 (1.8%)
Attack Complexity
Low44 (77.2%)
High4 (7.0%)
Unknown9 (15.8%)
User Interaction
None45 (78.9%)
Unknown9 (15.8%)
Required3 (5.3%)
Privileges Required
Low17 (29.8%)
High2 (3.5%)
None29 (50.9%)
Unknown9 (15.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (57 CVEs).

CISA KEV
5 CVEs
8.8% of CVEs· 100th percentile
Metasploit
3 CVEs
5.3% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
8.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Opengroup.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Opengroup — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Opengroup's Products

View all 11 CNAs →

Top CWEs