Enterprise Linux Server Eus
Vendor:
First CVE: Nov 17, 2010 · Active for 15 years
625
Total CVEs
More Total CVEs than 100% of tracked products
48.1
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
1.4%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Enterprise Linux Server Eus over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 17, 2010
15 years ago
Most Recent CVE
Aug 22, 2022
1,432 days ago
CVE Severity & Scoring
Enterprise Linux Server Eus625 CVEs
29%
43%
24%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local143 (22.9%)
Network369 (59.0%)
Unknown105 (16.8%)
Physical3 (0.5%)
Adjacent Network5 (0.8%)
Attack Complexity
Low458 (73.3%)
High62 (9.9%)
Unknown105 (16.8%)
User Interaction
None375 (60.0%)
Unknown105 (16.8%)
Required145 (23.2%)
Privileges Required
Low91 (14.6%)
High13 (2.1%)
None416 (66.6%)
Unknown105 (16.8%)
Top CVEs
Signals from CVEs in this product scope (625 CVEs).
625 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0160HIGH The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive inform | Apr 7, 2014 | 7.5 | 99 | YES | YES |
CVE-2021-4034HIGH A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as pri | Jan 28, 2022 | 7.8 | 98 | YES | YES |
CVE-2015-5122CRITICAL Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 1 | Jul 14, 2015 | 9.8 | 98 | YES | YES |
CVE-2019-5544CRITICAL OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maxi | Dec 6, 2019 | 9.8 | 97 | YES | YES |
CVE-2016-9079HIGH A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users | Jun 11, 2018 | 7.5 | 97 | YES | YES |
CVE-2016-3427CRITICAL Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and avai | Apr 21, 2016 | 9.8 | 95 | YES | NO |
CVE-2018-17456CRITICAL Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing o | Oct 6, 2018 | 9.8 | 91 | NO | YES |
CVE-2018-16509HIGH An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers ab | Sep 5, 2018 | 7.8 | 88 | NO | YES |
CVE-2014-1510CRITICAL The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbit | Mar 19, 2014 | 9.8 | 87 | NO | YES |
CVE-2017-5645CRITICAL In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payloa | Apr 17, 2017 | 9.8 | 86 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (625 CVEs).
CISA KEV
9 CVEs
1.4% of CVEs· 96th percentile
Metasploit
14 CVEs
2.2% of CVEs· 96th percentile
Nuclei
4 CVEs
0.6% of CVEs· 96th percentile
ExploitDB
44 CVEs
7.0% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (625 CVEs).
Media Mentions
Signals from CVEs in this product scope (625 CVEs).
Top CNAs Publishing CVEs For Enterprise Linux Server Eus
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.6 | 2 | 5.5 | 0.4% | 0 | 0 |
| 8.4 | 2 | 8.4 | 53.6% | 1 | 1 |
| 8.1 | 8 | 7.4 | 0.9% | 0 | 0 |
| 7.7 | 49 | 7.2 | 6.2% | 1 | 4 |
| 7.6 | 280 | 7.3 | 7.5% | 1 | 23 |
| 7.5 | 348 | 7.6 | 7.0% | 2 | 22 |
| 7.4 | 259 | 7.7 | 7.2% | 1 | 18 |
| 7.3 | 175 | 7.7 | 6.5% | 1 | 13 |
| 7.2 | 85 | 6.8 | 11.7% | 1 | 9 |
| 7.1 | 58 | 6.9 | 8.7% | 0 | 2 |
| 6.7.z | 10 | 6.7 | 5.7% | 0 | 0 |
| 6.7 | 22 | 7.6 | 18.4% | 2 | 4 |
| 6.6.z | 16 | 6.3 | 5.0% | 0 | 0 |
| 6.6z | 1 | 5.5 | 0.4% | 0 | 0 |
| 6.6 | 13 | 8.0 | 13.8% | 2 | 1 |
| 6.5.z | 2 | 7.0 | 8.1% | 0 | 0 |
| 6.5 | 33 | 8.4 | 13.9% | 1 | 4 |
| 6.4.z | 2 | 5.7 | 6.5% | 0 | 0 |
| 6.4 | 15 | 9.4 | 9.7% | 0 | 0 |
| 6.3.z | 1 | 6.8 | 3.7% | 0 | 0 |