Package Hub

Vendor:

First CVE: Mar 29, 2016 · Active for 10 years

39
Total CVEs
More Total CVEs than 97% of tracked products
9.8
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 45% of tracked products
2.6%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Package Hub over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 29, 2016
10 years ago
Most Recent CVE
Aug 19, 2020
2,166 days ago

CVE Severity & Scoring

Package Hub39 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local2 (5.1%)
Network37 (94.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low38 (97.4%)
High1 (2.6%)
Unknown0 (0.0%)
User Interaction
None10 (25.6%)
Unknown0 (0.0%)
Required29 (74.4%)
Privileges Required
Low6 (15.4%)
High0 (0.0%)
None33 (84.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (39 CVEs).

39 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows re
Mar 29, 20168.886YESNO
A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are
Jul 23, 20196.532NONO
Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we pres
Jul 23, 20199.831NONO
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Dec 10, 20198.829NONO
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Dec 10, 20198.829NONO
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain que
Mar 22, 20208.028NONO
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
Dec 24, 20197.528NONO
flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer
Dec 24, 20197.528NONO
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and li
Mar 22, 20208.027NONO
Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Feb 11, 20208.827NONO

Exploit Exposure

Signals from CVEs in this product scope (39 CVEs).

CISA KEV
1 CVE
2.6% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (39 CVEs).

Media Mentions

Signals from CVEs in this product scope (39 CVEs).

Top CNAs Publishing CVEs For Package Hub

Top CWEs

Versions

No cataloged versions.