Database

Vendor:

First CVE: Apr 16, 2008 · Active for 18 years

66
Total CVEs
More Total CVEs than 98% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Database over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 16, 2008
18 years ago
Most Recent CVE
Apr 18, 2023
1,193 days ago

CVE Severity & Scoring

Database66 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local17 (25.8%)
Network47 (71.2%)
Unknown2 (3.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low54 (81.8%)
High10 (15.2%)
Unknown2 (3.0%)
User Interaction
None53 (80.3%)
Unknown2 (3.0%)
Required11 (16.7%)
Privileges Required
Low24 (36.4%)
High19 (28.8%)
None21 (31.8%)
Unknown2 (3.0%)

Top CVEs

Signals from CVEs in this product scope (66 CVEs).

66 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain clear
Oct 15, 20143.478NOYES
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which mak
Sep 1, 20167.577NONO
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a f
May 20, 20207.066NOYES
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amo
Mar 1, 20217.533NONO
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.4, and Dell BSAFE Micro Edition Suite, versions before 4.4, contain an Improper Input Validation Vulnerability.
Jul 11, 20229.832NONO
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Improper Input Validation Vulnerability.
Jul 11, 20229.831NONO
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain a Use of Insufficiently Random Values Vulnerability.
Jul 11, 20229.831NONO
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input Validation Vulnerability.
Jul 11, 20229.831NONO
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.
Jul 11, 20229.831NONO
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
Jul 11, 20229.830NONO

Exploit Exposure

Signals from CVEs in this product scope (66 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.5% of CVEs· 96th percentile
Nuclei
1 CVE
1.5% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (66 CVEs).

Media Mentions

Signals from CVEs in this product scope (66 CVEs).

Top CNAs Publishing CVEs For Database

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.2.0.8dv19.02.6%00
9.2.0.819.02.6%00
9.0.1.519.02.6%00
3.2.1.00.1016.01.0%00
21c237.34.3%01
19d14.11.2%00
19c386.53.3%01
18c125.91.8%00
12.2.0.1256.04.6%01
12.1.0.2516.65.0%01
12.1.0.175.81.4%00
11.2.0.4186.512.3%01
10.2.0.319.02.6%00
10.1.0.519.02.6%00