CVE Tools

Cmu

8 CVEs tracked since 2000. Since Apr 2000, none of them reached CISA KEV.

Cmu CVEs per month

Apr 2000 to Jan 2014. Point at a month, or focus the strip and use the arrow keys.
Cmu CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2000-0410
2000-05null or fewer
2000-06null or fewer
2000-07null or fewer
2000-08null or fewer
2000-09null or fewer
2000-10null or fewer
2000-11null or fewer
2000-12null or fewer
2001-01null or fewer
2001-02null or fewer
2001-03null or fewer
2001-04null or fewer
2001-05null or fewer
2001-06null or fewer
2001-07null or fewer
2001-08null or fewer
2001-09null or fewer
2001-10null or fewer
2001-11null or fewer
2001-12null or fewer
2002-01null or fewer
2002-02null or fewer
2002-03null or fewer
2002-04null or fewer
2002-05null or fewer
2002-06null or fewer
2002-07null or fewer
2002-08null or fewer
2002-09null or fewer
2002-10null or fewer
2002-11null or fewer
2002-12null or fewer
2003-01null or fewer
2003-02null or fewer
2003-03null or fewer
2003-04null or fewer
2003-05null or fewer
2003-06null or fewer
2003-07null or fewer
2003-08null or fewer
2003-09null or fewer
2003-10null or fewer
2003-11null or fewer
2003-12null or fewer
2004-01null or fewer
2004-02null or fewer
2004-03null or fewer
2004-04null or fewer
2004-05null or fewer
2004-06null or fewer
2004-07null or fewer
2004-08null or fewer
2004-09null or fewer
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01null or fewer
2005-02null or fewer
2005-03null or fewer
2005-04null or fewer
2005-05null or fewer
2005-06null or fewer
2005-07null or fewer
2005-08null or fewer
2005-09null or fewer
2005-10null or fewer
2005-11null or fewer
2005-12null or fewer
2006-01null or fewer
2006-02null or fewer
2006-03null or fewer
2006-04null or fewer
2006-05null or fewer
2006-06null or fewer
2006-07null or fewer
2006-08null or fewer
2006-09null or fewer
2006-10null or fewer
2006-11null or fewer
2006-12null or fewer
2007-01null or fewer
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-05null or fewer
2007-06null or fewer
2007-07null or fewer
2007-08null or fewer
2007-09null or fewer
2007-10null or fewer
2007-11null or fewer
2007-12null or fewer
2008-01null or fewer
2008-02null or fewer
2008-03null or fewer
2008-04null or fewer
2008-05null or fewer
2008-06null or fewer
2008-07null or fewer
2008-08null or fewer
2008-09null or fewer
2008-10null or fewer
2008-11null or fewer
2008-12null or fewer
2009-01null or fewer
2009-02null or fewer
2009-03null or fewer
2009-0410
2009-05null or fewer
2009-06null or fewer
2009-07null or fewer
2009-08null or fewer
2009-0910
2009-10null or fewer
2009-11null or fewer
2009-12null or fewer
2010-01null or fewer
2010-02null or fewer
2010-03null or fewer
2010-04null or fewer
2010-05null or fewer
2010-06null or fewer
2010-07null or fewer
2010-08null or fewer
2010-09null or fewer
2010-10null or fewer
2010-11null or fewer
2010-12null or fewer
2011-01null or fewer
2011-02null or fewer
2011-03null or fewer
2011-04null or fewer
2011-0510
2011-06null or fewer
2011-07null or fewer
2011-08null or fewer
2011-0920
2011-10null or fewer
2011-11null or fewer
2011-12null or fewer
2012-01null or fewer
2012-02null or fewer
2012-03null or fewer
2012-04null or fewer
2012-05null or fewer
2012-06null or fewer
2012-07null or fewer
2012-08null or fewer
2012-09null or fewer
2012-10null or fewer
2012-11null or fewer
2012-12null or fewer
2013-01null or fewer
2013-02null or fewer
2013-03null or fewer
2013-04null or fewer
2013-05null or fewer
2013-06null or fewer
2013-07null or fewer
2013-08null or fewer
2013-09null or fewer
2013-1010
2013-11null or fewer
2013-12null or fewer
2014-0110

Products

The products that kept showing up in Cmu's monthly top three, with their CVEs summed over those months.

  1. Cyrus Imap Server43 months
  2. Bootpd11 month
  3. Cyrus-sasl11 month
  4. Dbd\11 month
  5. Flite11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Cmu.

  1. CVE-2026-35467Private Key stored as extractable in browser IndexeDB7.5
  2. CVE-2026-35466Stored XSS via unsanitized input from remote service6.1
  3. CVE-2026-22188Panda3D <= 1.10.16 Deploy-Stub Stack Exhaustion via Unbounded alloca()5.5
  4. CVE-2026-22190Panda3D <= 1.10.16 egg-mkfont Format String Information Disclosure7.5
  5. CVE-2026-22189Panda3D <= 1.10.16 egg-mkfont Stack Buffer Overflow9.8
  6. CVE-2025-27092Path Traversal Vulnerability in GHOSTS Photo Retrieval Endpoint7.5
  7. CVE-2022-31506The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.9.3
  8. CVE-2014-7723The Carnegie Mellon Silicon Valley (aka edu.cmu.sv.mobile) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers...5.4
  9. CVE-2014-0027The play_wave_from_socket function in audio/auserver.c in Flite 1.4 allows local users to modify arbitrary files via a symlink attack on /tmp/awb.wav. NOTE: some of these details are obtained from...3.3
  10. CVE-2013-4122Cyrus SASL 2.1.23, 2.1.26, and earlier does not properly handle when a NULL value is returned upon an error by the crypt function as implemented in glibc 2.17 and later, which allows remote attacke...4.3
  11. CVE-2011-3208Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a cra...7.5
  12. CVE-2011-3481The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer derefere...4.3
  13. CVE-2011-1926The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sendin...5.1
  14. CVE-2009-2632Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users ...4.4
  15. CVE-2009-0663Heap-based buffer overflow in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module 1.49 for Perl might allow context-dependent attackers to execute arbitrary code via unspecified input to an applicati...7.5

The record

Peak rank
#31 in Apr 2000
Busiest month shown
Sep 2011, 2 CVEs
Months with a KEV entry
0 since Apr 2000
Monthly snapshots
7 since 2000
Cmu's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store