Udev
Vendor:
First CVE: Apr 17, 2009 · Active for 17 years
4
Total CVEs
More Total CVEs than 72% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
5.0
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Udev over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 17, 2009
17 years ago
Most Recent CVE
Jan 25, 2011
5,658 days ago
CVE Severity & Scoring
Udev4 CVEs
25%
50%
25%
All CVEs352,101 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown4 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown4 (100.0%)
User Interaction
None0 (0.0%)
Unknown4 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown4 (100.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1185HIGH udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space. | Apr 17, 2009 | 7.2 | 84 | NO | YES |
CVE-2011-0640MEDIUM The default configuration of udev on Linux does not warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted attacke | Jan 25, 2011 | 6.9 | 23 | NO | NO |
CVE-2010-4176MEDIUM plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13 and 14, sets weak permissions for the /dev/systty device file, which allows remote authenticated users to read | Dec 7, 2010 | 4.0 | 17 | NO | NO |
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that t | Apr 17, 2009 | 2.1 | 13 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
25.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
25.0% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CNAs Publishing CVEs For Udev
Top CWEs
Versions
No cataloged versions.