Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Yottadb

First CVE: Feb 18, 2021Active for: 5 yearsTotal CVEs: 18
53.1
VTI Score
TOP TARGET

YottaDB is a distributed, open-source multi-model database system derived from GT.M that serves mission-critical applications in financial services and telecommunications, positioning it prominently within specialized infrastructure deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through memory-safety and input-handling weakness classes including NULL-pointer dereferences, buffer overflows, improper input validation, and arithmetic errors that are characteristic of systems-level database engines. Defenders managing YottaDB instances should prioritize patching cycles and validate input handling at application boundaries; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
4.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Yottadb over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 18, 2021
5 years ago
Most Recent CVE
Apr 15, 2022
1,561 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-44486CRITICAL
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can manipulate the value of a function pointer used in op_write in sr_port/op_write.c
Apr 15, 20229.829NONO
CVE-2021-27377CRITICAL
An issue was discovered in the yottadb crate before 1.2.0 for Rust. For some memory-allocation patterns, ydb_subscript_next_st and ydb_subscript_prev_st have a use-after-free.
Feb 18, 20219.829NONO
CVE-2021-44488CRITICAL
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can control the size and input to calls to memcpy in op_fnfnumber in sr_port/op_fnfnum
Apr 15, 20229.127NONO
CVE-2021-44494HIGH
An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointe
Apr 15, 20227.524NONO
CVE-2021-44492HIGH
An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, attackers can cause a type to be incorrectly initialized in the fu
Apr 15, 20227.524NONO
CVE-2021-44491HIGH
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c
Apr 15, 20227.524NONO
CVE-2021-44490HIGH
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c
Apr 15, 20227.524NONO
CVE-2021-44489HIGH
An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause an integer underflow of the size of calls to memset in op_fnj3 in sr_port/op
Apr 15, 20227.524NONO
CVE-2021-44487HIGH
An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in calls to ious_open in sr_unix/ious_open.c allows attackers to crash the application by deref
Apr 15, 20227.524NONO
CVE-2021-44484HIGH
An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in calls to emit_trip in sr_port/emit_code.c allows attackers to crash the application by deref
Apr 15, 20227.524NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
83%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None18 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None18 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Yottadb.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Yottadb — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Yottadb's Products

View all 1 CNAs →

Top CWEs