Enterprise Linux Server Eus

Vendor:

First CVE: Nov 17, 2010 · Active for 15 years

625
Total CVEs
More Total CVEs than 100% of tracked products
48.1
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
1.4%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Enterprise Linux Server Eus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 17, 2010
15 years ago
Most Recent CVE
Aug 22, 2022
1,432 days ago

CVE Severity & Scoring

Enterprise Linux Server Eus625 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local143 (22.9%)
Network369 (59.0%)
Unknown105 (16.8%)
Physical3 (0.5%)
Adjacent Network5 (0.8%)
Attack Complexity
Low458 (73.3%)
High62 (9.9%)
Unknown105 (16.8%)
User Interaction
None375 (60.0%)
Unknown105 (16.8%)
Required145 (23.2%)
Privileges Required
Low91 (14.6%)
High13 (2.1%)
None416 (66.6%)
Unknown105 (16.8%)

Top CVEs

Signals from CVEs in this product scope (625 CVEs).

625 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive inform
Apr 7, 20147.599YESYES
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as pri
Jan 28, 20227.898YESYES
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 1
Jul 14, 20159.898YESYES
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maxi
Dec 6, 20199.897YESYES
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users
Jun 11, 20187.597YESYES
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and avai
Apr 21, 20169.895YESNO
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing o
Oct 6, 20189.891NOYES
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers ab
Sep 5, 20187.888NOYES
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbit
Mar 19, 20149.887NOYES
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payloa
Apr 17, 20179.886NOYES

Exploit Exposure

Signals from CVEs in this product scope (625 CVEs).

CISA KEV
9 CVEs
1.4% of CVEs· 96th percentile
Metasploit
14 CVEs
2.2% of CVEs· 96th percentile
Nuclei
4 CVEs
0.6% of CVEs· 96th percentile
ExploitDB
44 CVEs
7.0% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (625 CVEs).

Media Mentions

Signals from CVEs in this product scope (625 CVEs).

Top CNAs Publishing CVEs For Enterprise Linux Server Eus

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.625.50.4%00
8.428.453.6%11
8.187.40.9%00
7.7497.26.2%14
7.62807.37.5%123
7.53487.67.0%222
7.42597.77.2%118
7.31757.76.5%113
7.2856.811.7%19
7.1586.98.7%02
6.7.z106.75.7%00
6.7227.618.4%24
6.6.z166.35.0%00
6.6z15.50.4%00
6.6138.013.8%21
6.5.z27.08.1%00
6.5338.413.9%14
6.4.z25.76.5%00
6.4159.49.7%00
6.3.z16.83.7%00