3com records
41 published records for vendor 3com.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 3 · 7.3%
- Pre-auth RCE
- 4
- With a fix record
- 2.4%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-16 Configuration2
- CWE-20 Improper Input Validation2
- CWE-399 Resource Management Errors2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-134 Use of Externally-Controlled Format String1
The weakness classes this vendor ships most often: where to look.
CWEAll records
41 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
61This week | CVE-2006-6183Weaponized | Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a denial of service (cr3com · 3ctftpsvc · CWE-119 | Critical10.0 | — | 70.3% | Nov 30, 2006 |
42Plan | CVE-2001-1291Proof of concept | The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect userna3com · superstack ii ps hub 40 firmware · CWE-307 | Critical9.8 | — | 8.9% | Jul 12, 2001 |
41Plan | CVE-2004-0477No exploit | Unknown vulnerability in 3Com OfficeConnect Remote 812 ADSL Router allows remote attackers to bypass authentication via repeated attempts us3com · 3cp4144 | Critical10.0 | — | 4.1% | Dec 6, 2004 |
41Plan | CVE-2007-5419No exploit | The 3Com 3CRWER100-75 router with 1.2.10ww software, when enabling an optional virtual server, configures this server to accept all source I3com · 3crwe554g72t · CWE-16 | Critical10.0 | — | 2.2% | Oct 12, 2007 |
40Plan | CVE-2004-2691Weaponized | Unspecified vulnerability in 3Com SuperStack 3 4400 switches with firmware version before 3.31 allows remote attackers to cause a denial of 3com · 3c17205-us | High7.1 | — | 39.1% | Dec 31, 2004 |
39Monitor | CVE-2005-0277Weaponized | Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash)3com · 3cdaemon | Medium5.0 | — | 61.9% | May 2, 2005 |
33Monitor | CVE-2002-0606Proof of concept | Buffer overflow in 3Cdaemon 2.0 FTP server allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code 3com · 3cdaemon | High7.5 | — | 10.6% | Jun 18, 2002 |
33Monitor | CVE-2007-3701Proof of concept | TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) character, which might allow remote attippingpoint · tipping point · CWE-20 | High7.5 | — | 8.5% | Jul 11, 2007 |
32Monitor | CVE-2002-2300Proof of concept | Buffer overflow in ftpd 5.4 in 3Com NBX 4.0.17 or ftpd 5.4.2 in 3Com NBX 4.1.4 allows remote attackers to cause a denial of service (crash) 3com · webbngss3nbxnts · CWE-119 | High7.5 | — | 5.0% | Dec 31, 2002 |
32Monitor | CVE-2008-6395No exploit | The web management interface in 3Com Wireless 8760 Dual Radio 11a/b/g PoE Access Point allows remote attackers to cause a denial of service 3com · wireless 8760 dual-radio · CWE-134 | High7.8 | — | 2.5% | Mar 4, 2009 |
32Monitor | CVE-2007-2276No exploit | 3Com TippingPoint IPS allows remote attackers to cause a denial of service (device hang) via a flood of packets on TCP port 80 with sequenti3com · tippingpoint ips · CWE-399 | High7.8 | — | 1.7% | Apr 25, 2007 |
31Monitor | CVE-2005-0419Proof of concept | Multiple heap-based buffer overflows in 3Com 3CServer allow remote authenticated users to execute arbitrary code via long FTP commands, as d3com · 3cserver | High7.5 | — | 3.9% | Apr 27, 2005 |
31Monitor | CVE-2004-1596Proof of concept | The 3COM Wireless router 3CRADSL72 running Boot Code 1.3d allows remote attackers to gain sensitive information such as passwords and router3com · 3cradsl72 | High7.5 | — | 2.6% | Oct 13, 2004 |
31Monitor | CVE-2007-2734No exploit | The 3Com TippingPoint IPS do not properly handle certain full-width and half-width Unicode character encodings in an HTTP POST request, whic3com · 3crtpx505-73 | High7.5 | — | 2.1% | May 16, 2007 |
31Monitor | CVE-2007-3711No exploit | Unspecified vulnerability in TOS 2.1.x, 2.2.x before 2.2.5, and 2.5.x before 2.5.2 on TippingPoint IPS allows remote attackers to avoid dete3com · tippingpoint ips tos · CWE-20 | High7.5 | — | 2.1% | Jul 11, 2007 |
31Monitor | CVE-2006-5382No exploit | 3Com Switch SS3 4400 switches, firmware 5.11, 6.00 and 6.10 and earlier, allow remote attackers to read the SNMP Read-Write Community string3com · superstack 3 switch 4400 | High7.5 | — | 1.7% | Oct 25, 2006 |
30Monitor | CVE-2002-0888No exploit | 3Com OfficeConnect Remote 812 ADSL Router, firmware 1.1.9 and 1.1.7, allows remote attackers to bypass port access restrictions by connectin3com · 3cp4144 | High7.5 | — | 1.6% | Oct 4, 2002 |
30Monitor | CVE-1999-1513No exploit | Management information base (MIB) for a 3Com SuperStack II hub running software version 2.10 contains an object identifier (.1.3.6.1.4.1.43.3com · superstack ii hub | High7.5 | — | 1.1% | Aug 30, 1999 |
30Monitor | CVE-1999-1389No exploit | US Robotics/3Com Total Control Chassis with Frame Relay between 3.6.22 and 3.7.24 does not properly enforce access filters when the "set hos3com · total control netserver card | High7.5 | — | 1.1% | May 11, 1998 |
27Monitor | CVE-2010-2103Proof of concept | Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.apache · axis2 · CWE-79 | Medium4.3 | — | 34.9% | May 27, 2010 |
21Monitor | CVE-2001-0740Proof of concept | 3COM OfficeConnect 812 and 840 ADSL Router 4.2, running OCR812 router software 1.1.9 and earlier, allows remote attackers to cause a denial 3com · 3c840-us | Medium5.0 | — | 4.1% | Oct 18, 2001 |
21Monitor | CVE-2001-1293No exploit | Buffer overflow in web server of 3com HomeConnect Cable Modem External with USB (#3CR29223) allows remote attackers to cause a denial of ser3com · 3cr29223 | Medium5.0 | — | 3.6% | Sep 26, 2001 |
21Monitor | CVE-2006-0993No exploit | The web management interface in 3Com TippingPoint SMS Server before 2.2.1.4478 does not restrict access to certain directories, which might 3com · tippingpoint sms server | Medium5.0 | — | 2.7% | May 9, 2006 |
21Monitor | CVE-2004-1977No exploit | 3com NBX IP VOIP NetSet Configuration Manager allows remote attackers to cause a denial of service (crash) via a Nessus scan in safeChecks m3com · webbngss3nbxnts | Medium5.0 | — | 2.6% | Apr 29, 2004 |
21Monitor | CVE-2006-0362No exploit | TippingPoint Intrusion Prevention System (IPS) TOS before 2.1.4.6324, and TOS 2.2.x before 2.2.1.6506, allow remote attackers to cause a den3com · tippingpoint ips tos · CWE-399 | Medium5.0 | — | 1.9% | Jan 22, 2006 |
- CVE-2006-618361This week
Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a denial of service (cr
CriticalCVSS 10.0WeaponizedEPSS 70%3com · 3ctftpsvcNov 30, 2006
- CVE-2001-129142Plan
The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect userna
CriticalCVSS 9.8Proof of conceptEPSS 9%3com · superstack ii ps hub 40 firmwareJul 12, 2001
- CVE-2004-047741Plan
Unknown vulnerability in 3Com OfficeConnect Remote 812 ADSL Router allows remote attackers to bypass authentication via repeated attempts us
CriticalCVSS 10.0No exploitEPSS 4%3com · 3cp4144Dec 6, 2004
- CVE-2007-541941Plan
The 3Com 3CRWER100-75 router with 1.2.10ww software, when enabling an optional virtual server, configures this server to accept all source I
CriticalCVSS 10.0No exploitEPSS 2%3com · 3crwe554g72tOct 12, 2007
- CVE-2004-269140Plan
Unspecified vulnerability in 3Com SuperStack 3 4400 switches with firmware version before 3.31 allows remote attackers to cause a denial of
HighCVSS 7.1WeaponizedEPSS 39%3com · 3c17205-usDec 31, 2004
- CVE-2005-027739Monitor
Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash)
MediumCVSS 5.0WeaponizedEPSS 62%3com · 3cdaemonMay 2, 2005
- CVE-2002-060633Monitor
Buffer overflow in 3Cdaemon 2.0 FTP server allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code
HighCVSS 7.5Proof of conceptEPSS 11%3com · 3cdaemonJun 18, 2002
- CVE-2007-370133Monitor
TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) character, which might allow remote at
HighCVSS 7.5Proof of conceptEPSS 8%tippingpoint · tipping pointJul 11, 2007
- CVE-2002-230032Monitor
Buffer overflow in ftpd 5.4 in 3Com NBX 4.0.17 or ftpd 5.4.2 in 3Com NBX 4.1.4 allows remote attackers to cause a denial of service (crash)
HighCVSS 7.5Proof of conceptEPSS 5%3com · webbngss3nbxntsDec 31, 2002
- CVE-2008-639532Monitor
The web management interface in 3Com Wireless 8760 Dual Radio 11a/b/g PoE Access Point allows remote attackers to cause a denial of service
HighCVSS 7.8No exploitEPSS 3%3com · wireless 8760 dual-radioMar 4, 2009
- CVE-2007-227632Monitor
3Com TippingPoint IPS allows remote attackers to cause a denial of service (device hang) via a flood of packets on TCP port 80 with sequenti
HighCVSS 7.8No exploitEPSS 2%3com · tippingpoint ipsApr 25, 2007
- CVE-2005-041931Monitor
Multiple heap-based buffer overflows in 3Com 3CServer allow remote authenticated users to execute arbitrary code via long FTP commands, as d
HighCVSS 7.5Proof of conceptEPSS 4%3com · 3cserverApr 27, 2005
- CVE-2004-159631Monitor
The 3COM Wireless router 3CRADSL72 running Boot Code 1.3d allows remote attackers to gain sensitive information such as passwords and router
HighCVSS 7.5Proof of conceptEPSS 3%3com · 3cradsl72Oct 13, 2004
- CVE-2007-273431Monitor
The 3Com TippingPoint IPS do not properly handle certain full-width and half-width Unicode character encodings in an HTTP POST request, whic
HighCVSS 7.5No exploitEPSS 2%3com · 3crtpx505-73May 16, 2007
- CVE-2007-371131Monitor
Unspecified vulnerability in TOS 2.1.x, 2.2.x before 2.2.5, and 2.5.x before 2.5.2 on TippingPoint IPS allows remote attackers to avoid dete
HighCVSS 7.5No exploitEPSS 2%3com · tippingpoint ips tosJul 11, 2007
- CVE-2006-538231Monitor
3Com Switch SS3 4400 switches, firmware 5.11, 6.00 and 6.10 and earlier, allow remote attackers to read the SNMP Read-Write Community string
HighCVSS 7.5No exploitEPSS 2%3com · superstack 3 switch 4400Oct 25, 2006
- CVE-2002-088830Monitor
3Com OfficeConnect Remote 812 ADSL Router, firmware 1.1.9 and 1.1.7, allows remote attackers to bypass port access restrictions by connectin
HighCVSS 7.5No exploitEPSS 2%3com · 3cp4144Oct 4, 2002
- CVE-1999-151330Monitor
Management information base (MIB) for a 3Com SuperStack II hub running software version 2.10 contains an object identifier (.1.3.6.1.4.1.43.
HighCVSS 7.5No exploitEPSS 1%3com · superstack ii hubAug 30, 1999
- CVE-1999-138930Monitor
US Robotics/3Com Total Control Chassis with Frame Relay between 3.6.22 and 3.7.24 does not properly enforce access filters when the "set hos
HighCVSS 7.5No exploitEPSS 1%3com · total control netserver cardMay 11, 1998
- CVE-2010-210327Monitor
Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.
MediumCVSS 4.3Proof of conceptEPSS 35%apache · axis2May 27, 2010
- CVE-2001-074021Monitor
3COM OfficeConnect 812 and 840 ADSL Router 4.2, running OCR812 router software 1.1.9 and earlier, allows remote attackers to cause a denial
MediumCVSS 5.0Proof of conceptEPSS 4%3com · 3c840-usOct 18, 2001
- CVE-2001-129321Monitor
Buffer overflow in web server of 3com HomeConnect Cable Modem External with USB (#3CR29223) allows remote attackers to cause a denial of ser
MediumCVSS 5.0No exploitEPSS 4%3com · 3cr29223Sep 26, 2001
- CVE-2006-099321Monitor
The web management interface in 3Com TippingPoint SMS Server before 2.2.1.4478 does not restrict access to certain directories, which might
MediumCVSS 5.0No exploitEPSS 3%3com · tippingpoint sms serverMay 9, 2006
- CVE-2004-197721Monitor
3com NBX IP VOIP NetSet Configuration Manager allows remote attackers to cause a denial of service (crash) via a Nessus scan in safeChecks m
MediumCVSS 5.0No exploitEPSS 3%3com · webbngss3nbxntsApr 29, 2004
- CVE-2006-036221Monitor
TippingPoint Intrusion Prevention System (IPS) TOS before 2.1.4.6324, and TOS 2.2.x before 2.2.1.6506, allow remote attackers to cause a den
MediumCVSS 5.0No exploitEPSS 2%3com · tippingpoint ips tosJan 22, 2006