Scientific Linux maintains a narrowly scoped Linux distribution platform with a modest vulnerability footprint centered on the LUCI system-management interface. The durable signal reflects the management tool's multi-user and concurrent-execution context, with recurring weakness classes including race conditions in shared resources, code-injection flaws, and other implementation issues; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scientificlinux over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-3593MEDIUM Eval injection vulnerability in luci 0.26.0 allows remote authenticated users with certain permissions to execute arbitrary Python code via a crafted cluster configuration. | Oct 15, 2014 | 6.0 | 17 | NO | NO |
CVE-2013-4482MEDIUM Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0.26.0, when started using the initscript, allows local users to gain privileges via a Trojan horse | Nov 23, 2013 | 6.2 | 17 | NO | NO |
Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and o | Nov 23, 2013 | 1.9 | 11 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scientificlinux.
Media articles that mention a CVE ID that affects a product developed by Scientificlinux — matched by CVE ID, not by vendor name.