Backports Sle

Vendor:

First CVE: Nov 7, 2018 · Active for 7 years

329
Total CVEs
More Total CVEs than 100% of tracked products
65.8
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.9%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Backports Sle over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 7, 2018
7 years ago
Most Recent CVE
Sep 7, 2022
1,417 days ago

CVE Severity & Scoring

Backports Sle329 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local34 (10.3%)
Network295 (89.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low314 (95.4%)
High15 (4.6%)
Unknown0 (0.0%)
User Interaction
None93 (28.3%)
Unknown0 (0.0%)
Required236 (71.7%)
Privileges Required
Low36 (10.9%)
High1 (0.3%)
None292 (88.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (329 CVEs).

329 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_
May 4, 20209.896YESYES
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveragi
Feb 11, 20198.691NOYES
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP re
Jun 3, 20208.290NOYES
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Nov 3, 20209.688YESNO
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Nov 3, 20208.885YESNO
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob
Apr 20, 20196.178NOYES
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements
Oct 10, 20209.877NOYES
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go packa
Dec 14, 20188.163NONO
Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
May 23, 20197.536NOYES
Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.
Oct 7, 20209.835NONO

Exploit Exposure

Signals from CVEs in this product scope (329 CVEs).

CISA KEV
3 CVEs
0.9% of CVEs· 96th percentile
Metasploit
1 CVE
0.3% of CVEs· 96th percentile
Nuclei
3 CVEs
0.9% of CVEs· 96th percentile
ExploitDB
5 CVEs
1.5% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (329 CVEs).

Media Mentions

Signals from CVEs in this product scope (329 CVEs).

Top CNAs Publishing CVEs For Backports Sle

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
15.03267.44.7%37