Linux Enterprise Debuginfo

Vendor:

First CVE: Nov 13, 2008 · Active for 17 years

56
Total CVEs
More Total CVEs than 98% of tracked products
5.1
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 46% of tracked products
10.7%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Linux Enterprise Debuginfo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 13, 2008
17 years ago
Most Recent CVE
Jun 2, 2021
1,878 days ago

CVE Severity & Scoring

Linux Enterprise Debuginfo56 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local13 (23.2%)
Network29 (51.8%)
Unknown13 (23.2%)
Physical1 (1.8%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (71.4%)
High3 (5.4%)
Unknown13 (23.2%)
User Interaction
None31 (55.4%)
Unknown13 (23.2%)
Required12 (21.4%)
Privileges Required
Low8 (14.3%)
High1 (1.8%)
None34 (60.7%)
Unknown13 (23.2%)

Top CVEs

Signals from CVEs in this product scope (56 CVEs).

56 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code vi
Jan 13, 20108.897YESYES
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remo
Dec 15, 20097.897YESYES
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitr
Aug 8, 20158.896YESYES
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted ima
May 5, 20165.593YESYES
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
May 5, 20165.593YESYES
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
Oct 4, 20179.885NOYES
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
Apr 17, 20097.284NOYES
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attac
Feb 18, 20168.183NOYES
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability
Jul 16, 20159.879YESNO
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-a
Jan 3, 20189.860NONO

Exploit Exposure

Signals from CVEs in this product scope (56 CVEs).

CISA KEV
6 CVEs
10.7% of CVEs· 97th percentile
Metasploit
4 CVEs
7.1% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
16.1% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (56 CVEs).

Media Mentions

Signals from CVEs in this product scope (56 CVEs).

Top CNAs Publishing CVEs For Linux Enterprise Debuginfo

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
11.028.947.5%01
11487.327.1%68
1076.110.8%01