Enterprise Linux For Scientific Computing

Vendor:

First CVE: Jun 16, 2012 · Active for 14 years

71
Total CVEs
More Total CVEs than 98% of tracked products
5.9
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
12.7%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Enterprise Linux For Scientific Computing over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 16, 2012
14 years ago
Most Recent CVE
Jan 18, 2024
919 days ago

CVE Severity & Scoring

Enterprise Linux For Scientific Computing71 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local13 (18.3%)
Network55 (77.5%)
Unknown3 (4.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low63 (88.7%)
High5 (7.0%)
Unknown3 (4.2%)
User Interaction
None29 (40.8%)
Unknown3 (4.2%)
Required39 (54.9%)
Privileges Required
Low17 (23.9%)
High1 (1.4%)
None50 (70.4%)
Unknown3 (4.2%)

Top CVEs

Signals from CVEs in this product scope (71 CVEs).

71 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra
Sep 24, 20149.899YESYES
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as pri
Jan 28, 20227.898YESYES
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buff
Oct 28, 20199.898YESYES
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upl
Sep 19, 20178.198YESYES
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri
Sep 25, 20149.898YESYES
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Sep 16, 20219.097YESYES
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileser
Feb 21, 20228.870NONO
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addre
Mar 6, 20238.865YESNO
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the ns
May 16, 20136.561YESNO
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
Oct 22, 20155.357YESNO

Exploit Exposure

Signals from CVEs in this product scope (71 CVEs).

CISA KEV
9 CVEs
12.7% of CVEs· 98th percentile
Metasploit
3 CVEs
4.2% of CVEs· 96th percentile
Nuclei
3 CVEs
4.2% of CVEs· 97th percentile
ExploitDB
6 CVEs
8.5% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (71 CVEs).

Media Mentions

Signals from CVEs in this product scope (71 CVEs).

Top CNAs Publishing CVEs For Enterprise Linux For Scientific Computing

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.0327.623.1%87
6.0446.74.5%42