nasa CVE Vulnerabilities & Metrics

Focus on nasa vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About nasa Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with nasa. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total nasa CVEs: 18
Earliest CVE date: 09 Feb 2018, 23:29 UTC
Latest CVE date: 27 Sep 2024, 15:15 UTC

Latest CVE reference: CVE-2024-44912

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 3

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical nasa CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.16

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 6
4.0-6.9 11
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS nasa CVEs

These are the five CVEs with the highest CVSS scores for nasa, sorted by severity first and recency.

All CVEs for nasa

CVE-2024-44912 nasa vulnerability CVSS: 0 27 Sep 2024, 15:15 UTC

NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TM subsystem (crypto_tm.c).

CVE-2024-44911 nasa vulnerability CVSS: 0 27 Sep 2024, 15:15 UTC

NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TC subsystem (crypto_tc.c).

CVE-2024-44910 nasa vulnerability CVSS: 0 27 Sep 2024, 15:15 UTC

NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the AOS subsystem (crypto_aos.c).

CVE-2023-45885 nasa vulnerability CVSS: 0 09 Nov 2023, 17:15 UTC

Cross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary code via the new component feature in the flexibleLayout plugin.

CVE-2023-45884 nasa vulnerability CVSS: 0 09 Nov 2023, 17:15 UTC

Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.

CVE-2023-45282 nasa vulnerability CVSS: 0 06 Oct 2023, 19:15 UTC

In NASA Open MCT (aka openmct) before 3.1.0, prototype pollution can occur via an import action.

CVE-2022-23054 nasa vulnerability CVSS: 4.3 20 Feb 2022, 19:15 UTC

Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Summary Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

CVE-2022-23053 nasa vulnerability CVSS: 4.3 20 Feb 2022, 19:15 UTC

Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Condition Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

CVE-2022-22126 nasa vulnerability CVSS: 4.3 20 Feb 2022, 19:15 UTC

Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Web Page” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

CVE-2019-1010060 nasa vulnerability CVSS: 7.5 16 Jul 2019, 13:15 UTC

NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: remote unauthenticated attacker. The fixed version is: 3.43. NOTE: this CVE refers to the issues not covered by CVE-2018-3846, CVE-2018-3847, CVE-2018-3848, and CVE-2018-3849. One example is ftp_status in drvrnet.c mishandling a long string beginning with a '4' character.

CVE-2018-3847 nasa vulnerability CVSS: 6.8 01 Aug 2018, 19:29 UTC

Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3.42. Specially crafted images parsed via the library, can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.

CVE-2018-3849 nasa vulnerability CVSS: 6.8 16 Apr 2018, 16:29 UTC

In the ffghtb function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.

CVE-2018-3848 nasa vulnerability CVSS: 6.8 16 Apr 2018, 16:29 UTC

In the ffghbn function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.

CVE-2018-3846 nasa vulnerability CVSS: 6.8 16 Apr 2018, 16:29 UTC

In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.

CVE-2018-1000048 nasa vulnerability CVSS: 6.8 09 Feb 2018, 23:29 UTC

NASA RtRetrievalFramework version v1.0 contains a CWE-502 vulnerability in Data retrieval functionality of RtRetrieval framework that can result in remote code execution. This attack appear to be exploitable via Victim tries to retrieve and process a weather data file.

CVE-2018-1000047 nasa vulnerability CVSS: 6.8 09 Feb 2018, 23:29 UTC

NASA Kodiak version v1.0 contains a CWE-502 vulnerability in Kodiak library's data processing function that can result in remote code execution. This attack appear to be exploitable via Victim opens an untrusted file for optimization using Kodiak library.

CVE-2018-1000046 nasa vulnerability CVSS: 6.8 09 Feb 2018, 23:29 UTC

NASA Pyblock version v1.0 - v1.3 contains a CWE-502 vulnerability in Radar data parsing library that can result in remote code execution. This attack appear to be exploitable via Victim opening a specially crafted radar data file. This vulnerability appears to have been fixed in v1.4.

CVE-2018-1000045 nasa vulnerability CVSS: 6.8 09 Feb 2018, 23:29 UTC

NASA Singledop version v1.0 contains a CWE-502 vulnerability in NASA Singledop library (Weather data) that can result in remote code execution. This attack appear to be exploitable via Victim opening a specially crafted radar data file. This vulnerability appears to have been fixed in v1.1.