Secure Global Desktop

Vendor:

First CVE: Jun 15, 2013 · Active for 13 years

33
Total CVEs
More Total CVEs than 97% of tracked products
4.7
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 49% of tracked products
3.0%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Secure Global Desktop over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 15, 2013
13 years ago
Most Recent CVE
Oct 20, 2021
1,742 days ago

CVE Severity & Scoring

Secure Global Desktop33 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network28 (84.8%)
Unknown4 (12.1%)
Physical0 (0.0%)
Adjacent Network1 (3.0%)
Attack Complexity
Low21 (63.6%)
High8 (24.2%)
Unknown4 (12.1%)
User Interaction
None21 (63.6%)
Unknown4 (12.1%)
Required8 (24.2%)
Privileges Required
Low4 (12.1%)
High0 (0.0%)
None25 (75.8%)
Unknown4 (12.1%)

Top CVEs

Signals from CVEs in this product scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Sep 16, 20219.097YESYES
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projec
May 1, 20197.584NOYES
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the
Oct 4, 20184.383NOYES
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be m
Sep 26, 20196.182NOYES
Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtai
Jul 20, 20146.875NOYES
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the pos
Jul 12, 20215.361NONO
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between succes
Jul 13, 20179.160NONO
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms
Mar 25, 20215.957NONO
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input str
Jun 20, 20177.556NONO
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout com
Sep 25, 20185.947NONO

Exploit Exposure

Signals from CVEs in this product scope (33 CVEs).

CISA KEV
1 CVE
3.0% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
12.1% of CVEs· 97th percentile
ExploitDB
4 CVEs
12.1% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (33 CVEs).

Media Mentions

Signals from CVEs in this product scope (33 CVEs).

Top CNAs Publishing CVEs For Secure Global Desktop

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.6117.924.3%11
5.546.546.6%02
5.4126.532.8%03
5.348.138.0%00
5.247.82.9%00
5.125.955.9%01
5.025.955.9%01
4.7147.129.9%01
4.719.61.7%00
4.6337.239.1%01
4.416.120.5%01