Backports Sle
Vendor:
First CVE: Nov 7, 2018 · Active for 7 years
329
Total CVEs
More Total CVEs than 100% of tracked products
65.8
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.9%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Backports Sle over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 7, 2018
7 years ago
Most Recent CVE
Sep 7, 2022
1,417 days ago
CVE Severity & Scoring
Backports Sle329 CVEs
40%
52%
8%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local34 (10.3%)
Network295 (89.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low314 (95.4%)
High15 (4.6%)
Unknown0 (0.0%)
User Interaction
None93 (28.3%)
Unknown0 (0.0%)
Required236 (71.7%)
Privileges Required
Low36 (10.9%)
High1 (0.3%)
None292 (88.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (329 CVEs).
329 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-12641CRITICAL rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_ | May 4, 2020 | 9.8 | 96 | YES | YES |
CVE-2019-5736HIGH runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveragi | Feb 11, 2019 | 8.6 | 91 | NO | YES |
CVE-2020-13379HIGH The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP re | Jun 3, 2020 | 8.2 | 90 | NO | YES |
CVE-2020-15999CRITICAL Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Nov 3, 2020 | 9.6 | 88 | YES | NO |
CVE-2020-16009HIGH Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Nov 3, 2020 | 8.8 | 85 | YES | NO |
CVE-2019-11358MEDIUM jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob | Apr 20, 2019 | 6.1 | 78 | NO | YES |
CVE-2020-26935CRITICAL An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements | Oct 10, 2020 | 9.8 | 77 | NO | YES |
CVE-2018-16873HIGH In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go packa | Dec 14, 2018 | 8.1 | 63 | NO | NO |
CVE-2019-5796HIGH Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | May 23, 2019 | 7.5 | 36 | NO | YES |
CVE-2020-11800CRITICAL Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code. | Oct 7, 2020 | 9.8 | 35 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (329 CVEs).
CISA KEV
3 CVEs
0.9% of CVEs· 96th percentile
Metasploit
1 CVE
0.3% of CVEs· 96th percentile
Nuclei
3 CVEs
0.9% of CVEs· 96th percentile
ExploitDB
5 CVEs
1.5% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (329 CVEs).
Media Mentions
Signals from CVEs in this product scope (329 CVEs).
Top CNAs Publishing CVEs For Backports Sle
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 15.0 | 326 | 7.4 | 4.7% | 3 | 7 |