Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Unix

First CVE: Feb 22, 1999Active for: 27 yearsTotal CVEs: 40
47.1
VTI Score
High

Unix represents a foundational operating system and command environment that, despite its age and the consolidation of its variants into a small number of actively maintained distributions, remains a broadly deployed platform underlying critical infrastructure, cloud systems, and enterprise servers. The vulnerability disclosures affecting Unix recur across memory-safety and input-handling concerns—including buffer-boundary violations, information exposure, and cross-site scripting in web-facing contexts—that reflect the long history and complexity of the Unix ecosystem and its interaction with modern network services. While the raw CVE volume is modest relative to monolithic operating systems, the prominence of Unix in the vulnerability landscape stems from the depth of its deployment and the foundational role its core components play in downstream products and infrastructure. Defenders should treat Unix-attributed disclosures carefully, as fixes often propagate unevenly across the fragmented landscape of Unix variants and third-party distributions; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
40
Total CVEs
More Total CVEs than 98% of tracked vendors
4.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Unix over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 22, 1999
27 years ago
Most Recent CVE
Jan 2, 2013
4,951 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (40 CVEs).

40 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2009-3958HIGH
Multiple stack-based buffer overflows in the NOS Microsystems getPlus Helper ActiveX control before 1.6.2.49 in gp.ocx in the Download Manager in Adobe Reader and Acrobat 9.x befor
Jan 13, 201010.064NOYES
CVE-2011-4369HIGH
Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6 on Mac OS X, Adobe Reader and Acr
Dec 16, 201110.034NONO
CVE-2009-3954HIGH
The 3D implementation in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow attackers to execute arbitrary code via unspecified vector
Jan 13, 201010.031NONO
CVE-2009-3959HIGH
Integer overflow in the U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code
Jan 13, 201010.029NONO
CVE-2009-3956HIGH
The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecifi
Jan 13, 201010.027NONO
CVE-2009-1251HIGH
Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allows remote attackers to cause a denial of s
Apr 9, 200910.027NONO
CVE-2007-6045HIGH
Unspecified vulnerability in (1) DB2WATCH and (2) DB2FREEZE in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors.
Nov 20, 200710.025NONO
CVE-2007-6047HIGH
Unspecified vulnerability in the DB2DART tool in IBM DB2 UDB 9.1 before Fixpak 4 allows attackers to execute arbitrary commands as the DB2 instance owner, related to invocation of
Nov 20, 200710.025NONO
CVE-2007-6048HIGH
IBM DB2 UDB 9.1 before Fixpak 4 uses incorrect permissions on ACLs for DB2NODES.CFG, which has unknown impact and attack vectors. NOTE: the vendor description of this issue is too
Nov 20, 200710.025NONO
CVE-2007-6051HIGH
IBM DB2 UDB 9.1 before Fixpak 4 assigns incorrect privileges to the (1) DB2ADMNS and (2) DB2USERS alternative groups, which has unknown impact. NOTE: the vendor description of thi
Nov 20, 200710.025NONO
View all 40 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products40 CVEs
55%
43%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown40 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown40 (100.0%)
User Interaction
None0 (0.0%)
Unknown40 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown40 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (40 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
10.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Unix.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Unix — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Unix's Products

View all 3 CNAs →

Top CWEs