Vulnerabilities
Summary — last 7 days
New vulnerabilities2,744▼ 71 vs. last week
Critical / high1,416▲ 184 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)106▼ 394 vs. last week
9 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (7.8) | 0.33% | — | Sysstat Project SysstatFedoraproject FedoraDebian Linux | 5/18/2023 | 6/17/2026 | sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377. | |
| Modified | High (7.8) | 1.2% | — | Sysstat Project SysstatDebian LinuxFedoraproject Fedora | 11/8/2022 | 6/17/2026 | sysstat is a set of system performance tools for the Linux operating system. On 32 bit systems, in versions 9.1.16 and newer but prior to 12.7.1, allocate_structures contains a size_t overflow in sa_common.c. The allocate_structures function insufficiently checks bounds before arithmetic multiplication, allowing for… | |
| Modified | Critical (9.8) | 2.6% | — | Sysstat Project SysstatDebian LinuxCanonical Ubuntu Linux | 12/11/2019 | 6/17/2026 | sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c. | |
| Modified | Medium (5.5) | 1.5% | — | Sysstat Project SysstatFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+1 | 9/9/2019 | 6/17/2026 | sysstat before 12.1.6 has memory corruption due to an Integer Overflow in remap_struct() in sa_common.c. | |
| Modified | Medium (5.5) | 0.82% | — | Sysstat Project Sysstat | 11/24/2018 | 6/17/2026 | An issue was discovered in sysstat 12.1.1. The remap_struct function in sa_common.c has an out-of-bounds read during a memset call, as demonstrated by sadf. | |
| Modified | High (7.8) | 1.7% | — | Sysstat Project Sysstat | 11/21/2018 | 6/17/2026 | An issue was discovered in sysstat 12.1.1. The remap_struct function in sa_common.c has an out-of-bounds read during a memmove call, as demonstrated by sadf. | |
| Modified | Medium (4.4) | 0.42% | — | Sysstat | 8/14/2007 | 6/16/2026 | The init script (sysstat.in) in sysstat 5.1.2 up to 7.1.6 creates /tmp/sysstat.run insecurely, which allows local users to execute arbitrary code. | |
| Modified | Medium (4.6) | 0.36% | — | Redhat SysstatSGI PropackSysstat | 4/15/2004 | 6/16/2026 | The isag utility, which processes sysstat data, allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CAN-2004-0107. | |
| Modified | Medium (4.6) | 0.39% | — | Redhat SysstatSGI PropackSysstat | 4/15/2004 | 6/16/2026 | The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108. |