Unix represents a foundational operating system and command environment that, despite its age and the consolidation of its variants into a small number of actively maintained distributions, remains a broadly deployed platform underlying critical infrastructure, cloud systems, and enterprise servers. The vulnerability disclosures affecting Unix recur across memory-safety and input-handling concerns—including buffer-boundary violations, information exposure, and cross-site scripting in web-facing contexts—that reflect the long history and complexity of the Unix ecosystem and its interaction with modern network services. While the raw CVE volume is modest relative to monolithic operating systems, the prominence of Unix in the vulnerability landscape stems from the depth of its deployment and the foundational role its core components play in downstream products and infrastructure. Defenders should treat Unix-attributed disclosures carefully, as fixes often propagate unevenly across the fragmented landscape of Unix variants and third-party distributions; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unix over time
Signals from CVEs in this vendor scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3958HIGH Multiple stack-based buffer overflows in the NOS Microsystems getPlus Helper ActiveX control before 1.6.2.49 in gp.ocx in the Download Manager in Adobe Reader and Acrobat 9.x befor | Jan 13, 2010 | 10.0 | 64 | NO | YES |
CVE-2011-4369HIGH Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6 on Mac OS X, Adobe Reader and Acr | Dec 16, 2011 | 10.0 | 34 | NO | NO |
CVE-2009-3954HIGH The 3D implementation in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow attackers to execute arbitrary code via unspecified vector | Jan 13, 2010 | 10.0 | 31 | NO | NO |
CVE-2009-3959HIGH Integer overflow in the U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code | Jan 13, 2010 | 10.0 | 29 | NO | NO |
CVE-2009-3956HIGH The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecifi | Jan 13, 2010 | 10.0 | 27 | NO | NO |
CVE-2009-1251HIGH Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allows remote attackers to cause a denial of s | Apr 9, 2009 | 10.0 | 27 | NO | NO |
CVE-2007-6045HIGH Unspecified vulnerability in (1) DB2WATCH and (2) DB2FREEZE in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors. | Nov 20, 2007 | 10.0 | 25 | NO | NO |
CVE-2007-6047HIGH Unspecified vulnerability in the DB2DART tool in IBM DB2 UDB 9.1 before Fixpak 4 allows attackers to execute arbitrary commands as the DB2 instance owner, related to invocation of | Nov 20, 2007 | 10.0 | 25 | NO | NO |
CVE-2007-6048HIGH IBM DB2 UDB 9.1 before Fixpak 4 uses incorrect permissions on ACLs for DB2NODES.CFG, which has unknown impact and attack vectors. NOTE: the vendor description of this issue is too | Nov 20, 2007 | 10.0 | 25 | NO | NO |
CVE-2007-6051HIGH IBM DB2 UDB 9.1 before Fixpak 4 assigns incorrect privileges to the (1) DB2ADMNS and (2) DB2USERS alternative groups, which has unknown impact. NOTE: the vendor description of thi | Nov 20, 2007 | 10.0 | 25 | NO | NO |
Signals from CVEs in this vendor scope (40 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unix.
Media articles that mention a CVE ID that affects a product developed by Unix — matched by CVE ID, not by vendor name.