Openpkg is a narrowly focused but prominent platform for building and deploying enterprise software distributions, centered on a single core product line. Its vulnerability profile spans a diverse collection of weakness classes, ranging from memory-safety issues such as buffer overflows and double-free conditions to input-validation and argument-injection flaws affecting command handling. Vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting both the complexity of the components bundled in the distribution and the accessibility of proof-of-concept material for common weakness patterns. Defenders should monitor Openpkg advisories for embedded infrastructure and development environments where the platform is deployed; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openpkg over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0190MEDIUM OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine va | May 12, 2003 | 5.0 | 78 | NO | YES |
CVE-2004-0594MEDIUM The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute | Jul 27, 2004 | 5.1 | 51 | NO | YES |
CVE-2004-0990HIGH Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code | Mar 1, 2005 | 10.0 | 50 | NO | YES |
CVE-2004-0333HIGH Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME ar | Nov 23, 2004 | 10.0 | 48 | NO | YES |
CVE-2002-0083CRITICAL Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges. | Mar 15, 2002 | 9.8 | 48 | NO | YES |
CVE-2004-0416HIGH Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code. | Aug 6, 2004 | 10.0 | 41 | NO | YES |
CVE-2004-1471HIGH Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access to cause a denial of service (a | Dec 31, 2004 | 7.1 | 36 | NO | YES |
CVE-2004-1019HIGH The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unse | Jan 10, 2005 | 10.0 | 34 | NO | NO |
CVE-2004-1065HIGH Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image fi | Jan 10, 2005 | 10.0 | 34 | NO | NO |
CVE-2004-1012HIGH The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary code via a certain command ("body[p") that | Jan 10, 2005 | 10.0 | 32 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openpkg.
Media articles that mention a CVE ID that affects a product developed by Openpkg — matched by CVE ID, not by vendor name.