Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Socket/
  3. Socket

Socket

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 13 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Detects and blocks malicious/vulnerable open source packages in supply chains.

by Socket · socket.dev · source ↗

Known CVEs (13)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2003-0254 ↗MEDIUM 5.02003

    Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.

  • CVE-2003-0643 ↗LOW 2.12003

    Integer signedness error in the Linux Socket Filter implementation (filter.c) in Linux 2.4.3-pre3 to 2.4.22-pre10 allows attackers to cause a denial of service (crash).

  • CVE-2002-1372 ↗HIGH 7.52002

    Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of servi…

  • CVE-2002-1247 ↗HIGH 7.22002

    Buffer overflow in LISa allows local users to gain access to a raw socket via a long LOGNAME environment variable for the resLISa daemon.

  • CVE-2002-0497 ↗LOW 2.12002

    Buffer overflow in mtr 0.46 and earlier, when installed setuid root, allows local users to access a raw socket via a long MTR_OPTIONS environment variable.

  • CVE-2002-0518 ↗MEDIUM 5.02002

    The SYN cache (syncache) and SYN cookie (syncookie) mechanism in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (crash) (1) via a SYN packet that is accepted using syncoo…

  • CVE-2001-0178 ↗LOW 2.12001

    kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.

  • CVE-2000-0864 ↗MEDIUM 6.22000

    Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change the permissions of arbitrary files and directories, and gain additional privileg…

  • CVE-2000-1213 ↗HIGH 7.52000

    ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases ping's exposure to b…

  • CVE-1999-0787 ↗LOW 2.11999

    The SSH authentication agent follows symlinks via a UNIX domain socket.

  • CVE-2000-0489 ↗LOW 2.11999

    FreeBSD, NetBSD, and OpenBSD allow an attacker to cause a denial of service by creating a large number of socket pairs using the socketpair function, setting a large buffer size via setsockopt, then w…

  • CVE-1999-1402 ↗LOW 2.11997

    The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and p…

  • CVE-1999-1408 ↗LOW 2.11997

    Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socke…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Software Supply Chain Security products

see all →
  • Apiiro Deliver · Apiiro
  • Apiiro SSCS · Apiiro
  • Aqua Software Supply Chain Security · Aqua Security
  • BoostSecurity Cloud-speed Compliance · BoostSecurity
  • BoostSecurity Software Supply Chain Protection · BoostSecurity
  • CI/CD Security · Cycode
  • Chainguard Containers · Chainguard
  • Chainguard Libraries · Chainguard