Trustix operates a lean but well-represented portfolio centered on security-focused Linux distributions and antivirus software, positioning it among more prominent vendors in the endpoint protection landscape. The vendor's vulnerability disclosure pattern reflects the complexity of operating-system and threat-detection stacks: recurring weakness classes include improper input validation and memory-buffer handling issues, alongside a notably elevated tendency for public exploit code to emerge following disclosure. The exposure concentrates in its core secure Linux and antivirus products, where the intersection of kernel-level access and malware-detection heuristics creates a demanding attack surface. Defenders should track Trustix advisories for endpoint and host-security contexts; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Trustix over time
Signals from CVEs in this vendor scope (67 CVEs).
67 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2000-0917HIGH Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands. | Dec 19, 2000 | 10.0 | 84 | NO | YES |
CVE-2004-0493MEDIUM The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error lead | Aug 6, 2004 | 6.4 | 72 | NO | YES |
CVE-2004-0595MEDIUM The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows d | Jul 27, 2004 | 6.8 | 54 | NO | YES |
CVE-2000-0666HIGH rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges. | Jul 16, 2000 | 10.0 | 52 | NO | YES |
CVE-2004-0594MEDIUM The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute | Jul 27, 2004 | 5.1 | 51 | NO | YES |
CVE-2004-0600HIGH Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an invalid base-64 character during HTTP b | Jul 27, 2004 | 10.0 | 51 | NO | YES |
CVE-2004-0990HIGH Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code | Mar 1, 2005 | 10.0 | 50 | NO | YES |
CVE-2004-0989HIGH Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is no | Mar 1, 2005 | 10.0 | 49 | NO | YES |
CVE-2002-0083CRITICAL Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges. | Mar 15, 2002 | 9.8 | 48 | NO | YES |
CVE-2004-1304HIGH Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file. | Jan 10, 2005 | 10.0 | 47 | NO | YES |
Signals from CVEs in this vendor scope (67 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trustix.
Media articles that mention a CVE ID that affects a product developed by Trustix — matched by CVE ID, not by vendor name.