Communications Eagle Application Processor

Vendor:

First CVE: Jan 28, 2015 · Active for 11 years

12
Total CVEs
More Total CVEs than 90% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
8.3%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Communications Eagle Application Processor over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 28, 2015
11 years ago
Most Recent CVE
Mar 25, 2021
1,947 days ago

CVE Severity & Scoring

Communications Eagle Application Processor12 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local2 (16.7%)
Network9 (75.0%)
Unknown1 (8.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (83.3%)
High1 (8.3%)
Unknown1 (8.3%)
User Interaction
None7 (58.3%)
Unknown1 (8.3%)
Required4 (33.3%)
Privileges Required
Low3 (25.0%)
High0 (0.0%)
None8 (66.7%)
Unknown1 (8.3%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's
Apr 29, 20206.195YESYES
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code
Jan 28, 201510.092NOYES
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append
Apr 29, 20206.183NOYES
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob
Apr 20, 20196.178NOYES
A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An att
Mar 25, 20219.833NONO
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with
Jun 5, 20208.630NONO
Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
Jun 5, 20208.225NONO
The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
Mar 30, 20187.825NONO
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a spec
Jul 10, 20185.624NONO
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments an
Nov 8, 20196.123NONO

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
1 CVE
8.3% of CVEs· 97th percentile
Metasploit
1 CVE
8.3% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
33.3% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Communications Eagle Application Processor

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
16.2.026.74.5%00
16.1.026.74.5%00
16.028.248.1%01