Palm Os
Vendor:
First CVE: Dec 11, 2000 · Active for 25 years
6
Total CVEs
More Total CVEs than 79% of tracked products
1.2
Avg CVEs / Year
Higher CVE frequency than 58% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 12% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Palm Os over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 11, 2000
25 years ago
Most Recent CVE
Aug 21, 2007
6,916 days ago
CVE Severity & Scoring
Palm Os6 CVEs
83%
17%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown6 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown6 (100.0%)
User Interaction
None0 (0.0%)
Unknown6 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown6 (100.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0293MEDIUM PalmOS allows remote attackers to cause a denial of service (CPU consumption) via a flood of ICMP echo request (ping) packets. | Jun 16, 2003 | 5.0 | 24 | NO | YES |
CVE-2000-1008MEDIUM PalmOS 3.5.2 and earlier uses weak encryption to store the user password, which allows attackers with physical access to the Palm device to decrypt the password and gain access to | Dec 11, 2000 | 4.6 | 21 | NO | YES |
CVE-2007-4213HIGH Palm OS on Treo 650, 680, 700p, and 755p Smart phones allows remote attackers to cause a denial of service (device reset or hang) via a flood of large ICMP echo requests. NOTE: th | Aug 21, 2007 | 7.1 | 19 | NO | NO |
CVE-2002-0116MEDIUM Palm OS 3.5h and possibly other versions, as used in Handspring Visor and Xircom products, allows remote attackers to cause a denial of service via a TCP connect scan, e.g. from nm | Mar 25, 2002 | 5.0 | 15 | NO | NO |
CVE-2001-1438MEDIUM Handspring Visor 1.0 and 1.0.1 with the VisorPhone Springboard module installed allows remote attackers to cause a denial of service (PalmOS crash and VisorPhone database corruptio | Oct 22, 2001 | 5.0 | 15 | NO | NO |
CVE-2001-0157MEDIUM Debugging utility in the backdoor mode of Palm OS 3.5.2 and earlier allows attackers with physical access to a Palm device to bypass access restrictions and obtain passwords, even | Jun 2, 2001 | 4.6 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
33.3% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Palm Os
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.5h | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.5.2 | 1 | 4.6 | 0.7% | 0 | 0 |