Enterprise Linux Hpc Node

Vendor:

First CVE: May 3, 2012 · Active for 14 years

149
Total CVEs
More Total CVEs than 99% of tracked products
24.8
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 31% of tracked products
1.3%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Enterprise Linux Hpc Node over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 3, 2012
14 years ago
Most Recent CVE
Jul 25, 2017
3,286 days ago

CVE Severity & Scoring

Enterprise Linux Hpc Node149 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local24 (16.1%)
Network44 (29.5%)
Unknown81 (54.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low58 (38.9%)
High10 (6.7%)
Unknown81 (54.4%)
User Interaction
None58 (38.9%)
Unknown81 (54.4%)
Required10 (6.7%)
Privileges Required
Low16 (10.7%)
High1 (0.7%)
None51 (34.2%)
Unknown81 (54.4%)

Top CVEs

Signals from CVEs in this product scope (149 CVEs).

149 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted ima
May 5, 20165.593YESYES
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
May 5, 20165.593YESYES
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attac
Feb 18, 20168.183NOYES
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obta
May 5, 20165.979NOYES
The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memor
May 5, 20169.875NONO
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presen
Jul 19, 20168.154NONO
Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap
May 5, 20167.546NONO
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.
May 5, 20165.540NOYES
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial
May 5, 20167.540NONO
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a symlink attack on (1) /var/tmp/ab
Jun 26, 20177.838NOYES

Exploit Exposure

Signals from CVEs in this product scope (149 CVEs).

CISA KEV
2 CVEs
1.3% of CVEs· 96th percentile
Metasploit
2 CVEs
1.3% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
10 CVEs
6.7% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (149 CVEs).

Media Mentions

Signals from CVEs in this product scope (149 CVEs).

Top CNAs Publishing CVEs For Enterprise Linux Hpc Node

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.01206.510.4%29
6.0576.612.2%25
6156.36.7%00