RPM Software Management maintains foundational package-management and build-testing utilities for Linux distributions, with a vulnerability footprint centered on tools such as DNF5 and Mock that are integral to software-distribution pipelines. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rpm Software Management over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6395CRITICAL The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. T | Jan 16, 2024 | 9.8 | 24 | NO | NO |
CVE-2024-1930MEDIUM No Limit on Number of Open Sessions / Bad Session Close Behaviour in dnf5daemon-server before 5.1.17 allows a malicious user to impact Availability via No Limit on Number of Open | May 8, 2024 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rpm Software Management.
Media articles that mention a CVE ID that affects a product developed by Rpm Software Management — matched by CVE ID, not by vendor name.