Backports
Vendor:
First CVE: Dec 26, 2018 · Active for 7 years
97
Total CVEs
More Total CVEs than 99% of tracked products
24.3
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Backports over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 26, 2018
7 years ago
Most Recent CVE
Feb 19, 2022
1,616 days ago
CVE Severity & Scoring
Backports97 CVEs
51%
41%
8%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local13 (13.4%)
Network84 (86.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low96 (99.0%)
High1 (1.0%)
Unknown0 (0.0%)
User Interaction
None19 (19.6%)
Unknown0 (0.0%)
Required78 (80.4%)
Privileges Required
Low8 (8.2%)
High1 (1.0%)
None88 (90.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (97 CVEs).
97 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5789HIGH An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process t | May 23, 2019 | 8.8 | 42 | NO | YES |
CVE-2019-5788HIGH An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer proce | May 23, 2019 | 8.8 | 42 | NO | YES |
CVE-2020-15803MEDIUM Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget. | Jul 17, 2020 | 6.1 | 37 | NO | NO |
CVE-2018-20177CRITICAL rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in the function rdp_in_unistr() and results in memory corruption | Mar 15, 2019 | 9.8 | 33 | NO | NO |
CVE-2018-19873CRITICAL An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data. | Dec 26, 2018 | 9.8 | 32 | NO | NO |
CVE-2020-6493CRITICAL Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escap | Jun 3, 2020 | 9.6 | 31 | NO | NO |
CVE-2019-19951CRITICAL In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c. | Dec 24, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-19950CRITICAL In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c. | Dec 24, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-5827HIGH Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Jun 27, 2019 | 8.8 | 29 | NO | NO |
CVE-2019-5811HIGH Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page. | Jun 27, 2019 | 8.8 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (97 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
2.1% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (97 CVEs).
Media Mentions
Signals from CVEs in this product scope (97 CVEs).
Top CNAs Publishing CVEs For Backports
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| sle-15 | 96 | 7.1 | 2.3% | 0 | 2 |