viewvc kayıtları
viewvc üreticisine ait 21 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %61,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
- CWE-399 Resource Management Errors1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
21 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2010-0005İstismar yok | query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, whiviewvc · viewvc · CWE-264 | Yüksek7,5 | — | %1,7 | 29 Oca 2010 |
30İzleyin | CVE-2007-5743İstismar yok | viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.viewvc · viewvc · CWE-732 | Yüksek7,5 | — | %1,1 | 7 Kas 2019 |
30İzleyin | CVE-2025-54141İstismar yok | ViewVC's standalone server exposes arbitrary server filesystem contentviewvc · viewvc · CWE-22 | Yüksek7,5 | — | %0,9 | 22 Tem 2025 |
27İzleyin | CVE-2006-5442İstismar yok | ViewVC 1.0.2 and earlier does not specify a charset in its HTTP headers or HTML documents, which allows remote attackers to conduct cross-siviewvc · viewvc | Orta6,8 | — | %1,5 | 20 Eki 2006 |
24İzleyin | CVE-2017-5938İstismar yok | Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows reviewvc · viewvc · CWE-79 | Orta6,1 | — | %1,3 | 15 Mar 2017 |
24İzleyin | CVE-2023-22456İstismar yok | ViewVC XSS vulnerability in revision view changed pathsviewvc · viewvc · CWE-79 | Orta6,1 | — | %0,7 | 3 Oca 2023 |
23İzleyin | CVE-2008-4325İstismar yok | lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which alviewvc · viewvc | Orta5,8 | — | %1,4 | 30 Eyl 2008 |
21İzleyin | CVE-2009-5024İstismar yok | ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumptviewvc · viewvc · CWE-399 | Orta5,0 | — | %2,6 | 23 May 2011 |
21İzleyin | CVE-2010-0004İstismar yok | ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discoveviewvc · viewvc · CWE-200 | Orta5,0 | — | %2,6 | 29 Oca 2010 |
21İzleyin | CVE-2012-3356İstismar yok | The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows rviewvc · viewvc · CWE-287 | Orta5,0 | — | %2,0 | 22 Tem 2012 |
21İzleyin | CVE-2012-3357İstismar yok | The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is copviewvc · viewvc · CWE-200 | Orta5,0 | — | %1,9 | 22 Tem 2012 |
21İzleyin | CVE-2009-3619İstismar yok | Unspecified vulnerability in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 has unknown impact and remote attack vectors related to "printing viewvc · viewvc | Orta5,0 | — | %1,8 | 9 Kas 2009 |
21İzleyin | CVE-2023-22464İstismar yok | ViewVC XSS vulnerability in revision view changed path "copyfrom" locationsviewvc · viewvc · CWE-79 | Orta5,4 | — | %0,6 | 4 Oca 2023 |
18İzleyin | CVE-2012-4533İstismar yok | Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before viewvc · viewvc · CWE-79 | Orta4,3 | — | %3,1 | 18 Kas 2012 |
18İzleyin | CVE-2010-0736İstismar yok | Cross-site scripting (XSS) vulnerability in the view_queryform function in lib/viewvc.py in ViewVC before 1.0.10, and 1.1.x before 1.1.4, alviewvc · viewvc · CWE-79 | Orta4,3 | — | %1,7 | 19 Mar 2010 |
17İzleyin | CVE-2009-3618İstismar yok | Cross-site scripting (XSS) vulnerability in viewvc.py in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 allows remote attackers to inject arbiviewvc · viewvc · CWE-79 | Orta4,3 | — | %1,6 | 9 Kas 2009 |
17İzleyin | CVE-2008-1291İstismar yok | ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read viewvc · viewvc · CWE-200 | Orta4,3 | — | %1,4 | 24 Mar 2008 |
17İzleyin | CVE-2008-1290İstismar yok | ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote attaviewvc · viewvc · CWE-200 | Orta4,3 | — | %1,4 | 24 Mar 2008 |
17İzleyin | CVE-2008-1292İstismar yok | ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtaiviewvc · viewvc · CWE-200 | Orta4,3 | — | %1,4 | 24 Mar 2008 |
14İzleyin | CVE-2020-5283İstismar yok | XSS vulnerability in CVS show_subdir_lastmod supportviewvc · viewvc · CWE-80 | Düşük3,5 | — | %1,2 | 2 Nis 2020 |
11İzleyin | CVE-2010-0132İstismar yok | Cross-site scripting (XSS) vulnerability in ViewVC 1.1 before 1.1.5 and 1.0 before 1.0.11, when the regular expression search functionality viewvc · viewvc · CWE-79 | Düşük2,6 | — | %2,3 | 31 Mar 2010 |
- CVE-2010-000531İzleyin
query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, whi
YüksekCVSS 7,5İstismar yokEPSS %2viewvc · viewvc29 Oca 2010
- CVE-2007-574330İzleyin
viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.
YüksekCVSS 7,5İstismar yokEPSS %1viewvc · viewvc7 Kas 2019
- CVE-2025-5414130İzleyin
ViewVC's standalone server exposes arbitrary server filesystem content
YüksekCVSS 7,5İstismar yokEPSS %1viewvc · viewvc22 Tem 2025
- CVE-2006-544227İzleyin
ViewVC 1.0.2 and earlier does not specify a charset in its HTTP headers or HTML documents, which allows remote attackers to conduct cross-si
OrtaCVSS 6,8İstismar yokEPSS %2viewvc · viewvc20 Eki 2006
- CVE-2017-593824İzleyin
Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows re
OrtaCVSS 6,1İstismar yokEPSS %1viewvc · viewvc15 Mar 2017
- CVE-2023-2245624İzleyin
ViewVC XSS vulnerability in revision view changed paths
OrtaCVSS 6,1İstismar yokEPSS %1viewvc · viewvc3 Oca 2023
- CVE-2008-432523İzleyin
lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which al
OrtaCVSS 5,8İstismar yokEPSS %1viewvc · viewvc30 Eyl 2008
- CVE-2009-502421İzleyin
ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumpt
OrtaCVSS 5,0İstismar yokEPSS %3viewvc · viewvc23 May 2011
- CVE-2010-000421İzleyin
ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discove
OrtaCVSS 5,0İstismar yokEPSS %3viewvc · viewvc29 Oca 2010
- CVE-2012-335621İzleyin
The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows r
OrtaCVSS 5,0İstismar yokEPSS %2viewvc · viewvc22 Tem 2012
- CVE-2012-335721İzleyin
The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is cop
OrtaCVSS 5,0İstismar yokEPSS %2viewvc · viewvc22 Tem 2012
- CVE-2009-361921İzleyin
Unspecified vulnerability in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 has unknown impact and remote attack vectors related to "printing
OrtaCVSS 5,0İstismar yokEPSS %2viewvc · viewvc9 Kas 2009
- CVE-2023-2246421İzleyin
ViewVC XSS vulnerability in revision view changed path "copyfrom" locations
OrtaCVSS 5,4İstismar yokEPSS %1viewvc · viewvc4 Oca 2023
- CVE-2012-453318İzleyin
Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before
OrtaCVSS 4,3İstismar yokEPSS %3viewvc · viewvc18 Kas 2012
- CVE-2010-073618İzleyin
Cross-site scripting (XSS) vulnerability in the view_queryform function in lib/viewvc.py in ViewVC before 1.0.10, and 1.1.x before 1.1.4, al
OrtaCVSS 4,3İstismar yokEPSS %2viewvc · viewvc19 Mar 2010
- CVE-2009-361817İzleyin
Cross-site scripting (XSS) vulnerability in viewvc.py in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 allows remote attackers to inject arbi
OrtaCVSS 4,3İstismar yokEPSS %2viewvc · viewvc9 Kas 2009
- CVE-2008-129117İzleyin
ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read
OrtaCVSS 4,3İstismar yokEPSS %1viewvc · viewvc24 Mar 2008
- CVE-2008-129017İzleyin
ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote atta
OrtaCVSS 4,3İstismar yokEPSS %1viewvc · viewvc24 Mar 2008
- CVE-2008-129217İzleyin
ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtai
OrtaCVSS 4,3İstismar yokEPSS %1viewvc · viewvc24 Mar 2008
- CVE-2020-528314İzleyin
XSS vulnerability in CVS show_subdir_lastmod support
DüşükCVSS 3,5İstismar yokEPSS %1viewvc · viewvc2 Nis 2020
- CVE-2010-013211İzleyin
Cross-site scripting (XSS) vulnerability in ViewVC 1.1 before 1.1.5 and 1.0 before 1.0.11, when the regular expression search functionality
DüşükCVSS 2,6İstismar yokEPSS %2viewvc · viewvc31 Mar 2010