Secure Linux

Vendor:

First CVE: Jul 16, 2000 · Active for 26 years

66
Total CVEs
More Total CVEs than 98% of tracked products
11.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Secure Linux over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 16, 2000
26 years ago
Most Recent CVE
Feb 13, 2007
7,101 days ago

CVE Severity & Scoring

Secure Linux66 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local1 (1.5%)
Network1 (1.5%)
Unknown64 (97.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (3.0%)
High0 (0.0%)
Unknown64 (97.0%)
User Interaction
None2 (3.0%)
Unknown64 (97.0%)
Required0 (0.0%)
Privileges Required
Low1 (1.5%)
High0 (0.0%)
None1 (1.5%)
Unknown64 (97.0%)

Top CVEs

Signals from CVEs in this product scope (66 CVEs).

66 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.
Dec 19, 200010.084NOYES
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error lead
Aug 6, 20046.472NOYES
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows d
Jul 27, 20046.854NOYES
rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges.
Jul 16, 200010.052NOYES
The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute
Jul 27, 20045.151NOYES
Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an invalid base-64 character during HTTP b
Jul 27, 200410.051NOYES
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code
Mar 1, 200510.050NOYES
Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is no
Mar 1, 200510.049NOYES
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
Mar 15, 20029.848NOYES
Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file.
Jan 10, 200510.047NOYES

Exploit Exposure

Signals from CVEs in this product scope (66 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
22 CVEs
33.3% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (66 CVEs).

Media Mentions

Signals from CVEs in this product scope (66 CVEs).

Top CNAs Publishing CVEs For Secure Linux

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.087.23.3%00
2.2297.45.4%05
2.1426.610.8%013
2.0456.510.2%014
244.01.4%01
1.5236.514.1%010
1.264.03.1%02
1.1126.111.7%06
1.0117.52.0%00
1.0310.040.1%03