Developer Tools
Vendor:
First CVE: Oct 5, 2017 · Active for 8 years
15
Total CVEs
More Total CVEs than 92% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 41% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Developer Tools over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 5, 2017
8 years ago
Most Recent CVE
Aug 26, 2022
1,428 days ago
CVE Severity & Scoring
Developer Tools15 CVEs
33%
60%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local7 (46.7%)
Network8 (53.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (73.3%)
High4 (26.7%)
Unknown0 (0.0%)
User Interaction
None13 (86.7%)
Unknown0 (0.0%)
Required2 (13.3%)
Privileges Required
Low8 (53.3%)
High0 (0.0%)
None7 (46.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9514HIGH Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over ea | Aug 13, 2019 | 7.5 | 65 | NO | NO |
CVE-2017-15041CRITICAL Go before 1.8.4 and 1.9.x before 1.9.1 allows "go get" remote command execution. Using custom domains, it is possible to arrange things so that example.com/pkg1 points to a Subvers | Oct 5, 2017 | 9.8 | 35 | NO | NO |
CVE-2019-16276HIGH Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling. | Sep 30, 2019 | 7.5 | 27 | NO | NO |
CVE-2019-17596HIGH Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as tra | Oct 24, 2019 | 7.5 | 26 | NO | NO |
CVE-2018-16871HIGH A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able t | Jul 30, 2019 | 7.5 | 26 | NO | NO |
CVE-2022-1227HIGH A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim | Apr 29, 2022 | 8.8 | 25 | NO | NO |
CVE-2021-3697HIGH A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs | Jul 6, 2022 | 7.0 | 24 | NO | NO |
CVE-2021-3744MEDIUM A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, which allows attackers to cause a denial of service (memory | Mar 4, 2022 | 5.5 | 21 | NO | NO |
CVE-2021-3669MEDIUM A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS. | Aug 26, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-0330HIGH A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user | Mar 25, 2022 | 7.8 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Developer Tools
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.0 | 15 | 7.0 | 7.8% | 0 | 0 |