Whois is a foundational command-line utility and protocol implementation for domain and IP address registry lookups, with a narrow but widely embedded presence across infrastructure tooling and Unix-like systems. The observed vulnerability profile is limited in volume and centers on the core whois utility itself, with weakness classification reflecting miscellaneous issues rather than a consistent structural pattern. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Whois over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0709HIGH Buffer overflow in the whois client, which is not setuid but is sometimes called from within CGI programs, may allow remote attackers to execute arbitrary code via a long command l | Oct 20, 2003 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Whois.
Media articles that mention a CVE ID that affects a product developed by Whois — matched by CVE ID, not by vendor name.