CVE Tools

Condor-project

17 CVEs tracked since 2008. Since Jul 2008, none of them reached CISA KEV.

Condor-project CVEs per month

Jul 2008 to Jun 2014. Point at a month, or focus the strip and use the arrow keys.
Condor-project CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2008-0710
2008-08null or fewer
2008-09null or fewer
2008-1040
2008-11null or fewer
2008-12null or fewer
2009-01null or fewer
2009-02null or fewer
2009-03null or fewer
2009-04null or fewer
2009-05null or fewer
2009-06null or fewer
2009-07null or fewer
2009-08null or fewer
2009-09null or fewer
2009-10null or fewer
2009-11null or fewer
2009-1210
2010-01null or fewer
2010-02null or fewer
2010-03null or fewer
2010-04null or fewer
2010-05null or fewer
2010-06null or fewer
2010-07null or fewer
2010-08null or fewer
2010-09null or fewer
2010-10null or fewer
2010-11null or fewer
2010-12null or fewer
2011-01null or fewer
2011-02null or fewer
2011-03null or fewer
2011-04null or fewer
2011-05null or fewer
2011-06null or fewer
2011-07null or fewer
2011-08null or fewer
2011-09null or fewer
2011-10null or fewer
2011-11null or fewer
2011-12null or fewer
2012-01null or fewer
2012-02null or fewer
2012-03null or fewer
2012-04null or fewer
2012-05null or fewer
2012-06null or fewer
2012-07null or fewer
2012-0810
2012-0950
2012-10null or fewer
2012-11null or fewer
2012-12null or fewer
2013-01null or fewer
2013-02null or fewer
2013-0310
2013-04null or fewer
2013-05null or fewer
2013-06null or fewer
2013-07null or fewer
2013-08null or fewer
2013-09null or fewer
2013-1020
2013-11null or fewer
2013-12null or fewer
2014-01null or fewer
2014-0210
2014-03null or fewer
2014-04null or fewer
2014-05null or fewer
2014-0610

Products

The products that kept showing up in Condor-project's monthly top three, with their CVEs summed over those months.

  1. Condor179 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Condor-project.

  1. CVE-2012-5390The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 does no properly check privileges, which allows remote attackers to gain priv...10.0
  2. CVE-2011-4930Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a deni...4.4
  3. CVE-2013-4255The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not properly handle attributes in a (1) PREEMPT, (2) SUSPEND, (3) CONTINUE, (4) WANT_VACATE, or (5) KILL policy that evaluat...3.5
  4. CVE-2009-5136The policy definition evaluator in Condor before 7.4.2 does not properly handle attributes in a WANT_SUSPEND policy that evaluate to an UNDEFINED state, which allows remote authenticated users to c...4.0
  5. CVE-2012-4462aviary/jobcontrol.py in Condor, as used in Red Hat Enterprise MRG 2.3, when removing a job, allows remote attackers to cause a denial of service (condor_schedd restart) via square brackets in the c...4.3
  6. CVE-2012-3493The command_give_request_ad function in condor_startd.V6/command.cpp Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 allows remote attackers to obtain sensitive information, and possibly control ...5.8
  7. CVE-2012-3492The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when they have weak permissions, which allows ...6.4
  8. CVE-2012-3491src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the permissions of jobs, which allows remote authenticated users to remove arbitrary idl...4.0
  9. CVE-2012-5197Multiple unspecified vulnerabilities in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 have unknown impact and attack vectors related to "error checking of system calls."10.0
  10. CVE-2012-5196Multiple buffer overflows in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 have unknown impact and attack vectors.10.0
  11. CVE-2012-3416Condor before 7.8.2 allows remote attackers to bypass host-based authentication and execute actions such as ALLOW_ADMINISTRATOR or ALLOW_WRITE by connecting from a system with a spoofed reverse DNS...10.0
  12. CVE-2009-4133Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue jobs as an arbitrary user, and thereby gain pri...6.5
  13. CVE-2008-3830Condor before 7.0.5 does not properly handle when the configuration specifies overlapping netmasks in allow or deny rules, which causes the rule to be ignored and allows attackers to bypass intende...7.2
  14. CVE-2008-3828Stack-based buffer overflow in the condor_ schedd daemon in Condor before 7.0.5 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.4.6
  15. CVE-2008-3826Unspecified vulnerability in Condor before 7.0.5 allows attackers to execute jobs as other users via unknown vectors.4.6

The record

Peak rank
#23 in Oct 2008
Busiest month shown
Sep 2012, 5 CVEs
Months with a KEV entry
0 since Jul 2008
Monthly snapshots
9 since 2008
Condor-project's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store