Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Openpkg

First CVE: Mar 15, 2002Active for: 24 yearsTotal CVEs: 27
62.6
VTI Score
TOP TARGET

Openpkg is a narrowly focused but prominent platform for building and deploying enterprise software distributions, centered on a single core product line. Its vulnerability profile spans a diverse collection of weakness classes, ranging from memory-safety issues such as buffer overflows and double-free conditions to input-validation and argument-injection flaws affecting command handling. Vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting both the complexity of the components bundled in the distribution and the accessibility of proof-of-concept material for common weakness patterns. Defenders should monitor Openpkg advisories for embedded infrastructure and development environments where the platform is deployed; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
5.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Openpkg over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2002
24 years ago
Most Recent CVE
Nov 7, 2007
6,834 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2003-0190MEDIUM
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine va
May 12, 20035.078NOYES
CVE-2004-0594MEDIUM
The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute
Jul 27, 20045.151NOYES
CVE-2004-0990HIGH
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code
Mar 1, 200510.050NOYES
CVE-2004-0333HIGH
Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME ar
Nov 23, 200410.048NOYES
CVE-2002-0083CRITICAL
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
Mar 15, 20029.848NOYES
CVE-2004-0416HIGH
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.
Aug 6, 200410.041NOYES
CVE-2004-1471HIGH
Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access to cause a denial of service (a
Dec 31, 20047.136NOYES
CVE-2004-1019HIGH
The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unse
Jan 10, 200510.034NONO
CVE-2004-1065HIGH
Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image fi
Jan 10, 200510.034NONO
CVE-2004-1012HIGH
The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary code via a certain command ("body[p") that
Jan 10, 200510.032NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
33%
59%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (3.7%)
Network2 (7.4%)
Unknown24 (88.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (11.1%)
High0 (0.0%)
Unknown24 (88.9%)
User Interaction
None3 (11.1%)
Unknown24 (88.9%)
Required0 (0.0%)
Privileges Required
Low1 (3.7%)
High0 (0.0%)
None2 (7.4%)
Unknown24 (88.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.7% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
29.6% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Openpkg.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Openpkg — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Openpkg's Products

View all 1 CNAs →

Top CWEs