Cygwin
This hub aggregates every CVE we track for Cygwin, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
5
CVEs tracked
1
Critical
4
High
0
In CISA KEV
Severity distribution
HIGH4CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 5 most recently published vulnerabilities affecting Cygwin.
- CVE-2017-7523Cygwin versions 1.7.2 up to and including 1.8.0 are vulnerable to buffer overflow vulnerability in wcsxfrm/wcsxfrm_l functions resulting into denial-of-service by crashing the process or potential ...7.5
- CVE-2016-3067Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain privileges.9.8
- CVE-2016-3125The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be u...7.5
- CVE-2008-3323setup.exe before 2.573.2.3 in Cygwin does not properly verify the authenticity of packages, which allows remote Cygwin mirror servers or man-in-the-middle attackers to execute arbitrary code via a ...7.6
- CVE-2007-6181Heap-based buffer overflow in cygwin1.dll in Cygwin 1.5.7 and earlier allows context-dependent attackers to execute arbitrary code via a filename with a certain length, as demonstrated by a remote ...8.5
Product normalization is registry-driven with AI assist and human review. How it works