Palmos
Vendor:
First CVE: Dec 11, 2000 · Active for 25 years
6
Total CVEs
Bottom 1%
1.2
Avg CVEs / Year
Bottom 1%
5.2
Avg CVSS
Higher Avg CVSS than 7% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Palmos over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 11, 2000
25 years ago
Most Recent CVE
Aug 21, 2007
6,914 days ago
CVE Severity & Scoring
Palmos6 CVEs
83%
17%
All CVEs352,719 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown6 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown6 (100.0%)
User Interaction
None0 (0.0%)
Unknown6 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown6 (100.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0293MEDIUM PalmOS allows remote attackers to cause a denial of service (CPU consumption) via a flood of ICMP echo request (ping) packets. | Jun 16, 2003 | 5.0 | 24 | NO | YES |
CVE-2000-1008MEDIUM PalmOS 3.5.2 and earlier uses weak encryption to store the user password, which allows attackers with physical access to the Palm device to decrypt the password and gain access to | Dec 11, 2000 | 4.6 | 21 | NO | YES |
CVE-2007-4213HIGH Palm OS on Treo 650, 680, 700p, and 755p Smart phones allows remote attackers to cause a denial of service (device reset or hang) via a flood of large ICMP echo requests. NOTE: th | Aug 21, 2007 | 7.1 | 19 | NO | NO |
CVE-2002-0116MEDIUM Palm OS 3.5h and possibly other versions, as used in Handspring Visor and Xircom products, allows remote attackers to cause a denial of service via a TCP connect scan, e.g. from nm | Mar 25, 2002 | 5.0 | 15 | NO | NO |
CVE-2001-1438MEDIUM Handspring Visor 1.0 and 1.0.1 with the VisorPhone Springboard module installed allows remote attackers to cause a denial of service (PalmOS crash and VisorPhone database corruptio | Oct 22, 2001 | 5.0 | 15 | NO | NO |
CVE-2001-0157MEDIUM Debugging utility in the backdoor mode of Palm OS 3.5.2 and earlier allows attackers with physical access to a Palm device to bypass access restrictions and obtain passwords, even | Jun 2, 2001 | 4.6 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
33.3% of CVEs· 93rd percentile
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Palmos
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.5h | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.5.2 | 1 | 4.6 | 0.7% | 0 | 0 |