Satellite

Vendor:

First CVE: Mar 30, 2007 · Active for 19 years

232
Total CVEs
More Total CVEs than 100% of tracked products
13.6
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 31% of tracked products
1.7%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Satellite over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 30, 2007
19 years ago
Most Recent CVE
Jul 1, 2026
26 days ago

CVE Severity & Scoring

Satellite232 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local24 (10.3%)
Network191 (82.3%)
Unknown16 (6.9%)
Physical0 (0.0%)
Adjacent Network1 (0.4%)
Attack Complexity
Low150 (64.7%)
High66 (28.4%)
Unknown16 (6.9%)
User Interaction
None143 (61.6%)
Unknown16 (6.9%)
Required73 (31.5%)
Privileges Required
Low50 (21.6%)
High14 (6.0%)
None152 (65.5%)
Unknown16 (6.9%)

Top CVEs

Signals from CVEs in this product scope (232 CVEs).

232 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and avai
Apr 21, 20169.895YESNO
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability
Jul 16, 20159.879YESNO
It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privile
Aug 9, 20189.869NONO
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
Oct 22, 20155.357YESNO
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remot
Apr 1, 20153.752NONO
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java
Apr 23, 20195.940NONO
A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user wi
Jul 1, 20268.839NONO
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability a
Apr 23, 20198.135NOYES
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability a
Apr 23, 20198.135NOYES

Exploit Exposure

Signals from CVEs in this product scope (232 CVEs).

CISA KEV
4 CVEs
1.7% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
2.2% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (232 CVEs).

Media Mentions

Signals from CVEs in this product scope (232 CVEs).

Top CNAs Publishing CVEs For Satellite

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.914.50.7%00
6.815.32.3%00
6.7.217.50.8%00
6.727.30.7%00
6.627.04.1%00
6.517.46.2%00
6.4147.22.7%00
6.367.01.7%00
6.1927.00.1%00
6.1816.50.4%00
6.1716.50.4%00
6.1616.50.4%00
6.1538.70.6%00
6.1429.80.8%00
6.1338.30.7%00
6.1114.50.7%00
6.1014.50.7%00
6.126.51.5%00
6.0.316.10.6%00
6.0346.64.0%11