Communications User Data Repository
Vendor:
First CVE: Mar 18, 2014 · Active for 12 years
6
Total CVEs
More Total CVEs than 83% of tracked products
1.2
Avg CVEs / Year
Higher CVE frequency than 58% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Communications User Data Repository over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 18, 2014
12 years ago
Most Recent CVE
Dec 18, 2021
1,683 days ago
CVE Severity & Scoring
Communications User Data Repository6 CVEs
50%
50%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network5 (83.3%)
Unknown1 (16.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (16.7%)
High4 (66.7%)
Unknown1 (16.7%)
User Interaction
None5 (83.3%)
Unknown1 (16.7%)
Required0 (0.0%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None4 (66.7%)
Unknown1 (16.7%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-0235HIGH Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code | Jan 28, 2015 | 10.0 | 92 | NO | YES |
CVE-2021-45105MEDIUM Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit | Dec 18, 2021 | 5.9 | 76 | NO | NO |
CVE-2016-5387HIGH The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY envir | Jul 19, 2016 | 8.1 | 57 | NO | NO |
CVE-2016-5385HIGH PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in | Jul 19, 2016 | 8.1 | 54 | NO | NO |
CVE-2016-2518MEDIUM The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode | Jan 30, 2017 | 5.3 | 26 | NO | NO |
CVE-2014-2532MEDIUM sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using | Mar 18, 2014 | 4.9 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
16.7% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
16.7% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Communications User Data Repository
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 12.4 | 1 | 5.9 | 100.0% | 0 | 0 |
| 12.0.0 | 2 | 6.7 | 32.8% | 0 | 0 |
| 10.0.1 | 3 | 6.1 | 23.4% | 0 | 0 |
| 10.0.0 | 2 | 6.7 | 32.8% | 0 | 0 |