Skip to content
Noroxi

cvstrac records

3 published records for vendor cvstrac.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

      The weakness classes this vendor ships most often: where to look.

      CWE

      All records

      3 records
      • CVE-2004-1456
        34Monitor

        filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.

        HighCVSS 7.5Proof of conceptEPSS 14%

        cvstrac · cvstracDec 31, 2004

      • CVE-2007-0347
        18Monitor

        The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authentic

        MediumCVSS 4.3Proof of conceptEPSS 4%

        cvstrac · cvstracJan 29, 2007

      • CVE-2004-1146
        17Monitor

        Multiple cross-site scripting (XSS) vulnerabilities in (1) main.c and (2) login.c for CVSTrac before 1.1.5 allow remote attackers to inject

        MediumCVSS 4.3No exploitEPSS 1%

        cvstrac · cvstracDec 31, 2004