extensis records
10 published records for vendor extensis.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-787 Out-of-bounds Write2
- CWE-20 Improper Input Validation1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-798 Use of Hard-coded Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2013-3944No exploit | Stack-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via extensis · mrsid · CWE-787 | High7.8 | — | 27.5% | Jan 2, 2020 |
36Monitor | CVE-2022-24254No exploit | An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execextensis · portfolio · CWE-434 | High8.8 | — | 2.6% | Mar 1, 2022 |
36Monitor | CVE-2022-24252No exploit | An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to executeextensis · portfolio · CWE-434 | High8.8 | — | 2.3% | Mar 1, 2022 |
35Monitor | CVE-2022-24255No exploit | Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.extensis · portfolio · CWE-798 | High8.8 | — | 1.4% | Mar 1, 2022 |
35Monitor | CVE-2022-24251No exploit | Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload functextensis · portfolio · CWE-434 | High8.8 | — | 1.3% | Mar 1, 2022 |
35Monitor | CVE-2022-24253No exploit | Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransfeextensis · portfolio · CWE-434 | High8.8 | — | 1.3% | Mar 1, 2022 |
32Monitor | CVE-2013-3946No exploit | Heap-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via aextensis · mrsid · CWE-787 | High7.8 | — | 2.5% | Jan 2, 2020 |
32Monitor | CVE-2013-3945No exploit | The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag.extensis · mrsid · CWE-20 | High7.8 | — | 2.1% | Jan 2, 2020 |
24Monitor | CVE-2017-18006No exploit | netpub/server.np in Extensis Portfolio NetPublish has XSS in the quickfind parameter, aka Open Bug Bounty ID OBB-290447.extensis · portfolio netpublish · CWE-79 | Medium6.1 | — | 0.7% | Dec 31, 2017 |
21Monitor | CVE-2005-4510Proof of concept | Directory traversal vulnerability in server.np in NetPublish Server 7 allows remote attackers to read arbitrary files via "../" sequences inextensis · netpublish server | Medium5.0 | — | 2.9% | Dec 22, 2005 |
- CVE-2013-394439Monitor
Stack-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via
HighCVSS 7.8No exploitEPSS 28%extensis · mrsidJan 2, 2020
- CVE-2022-2425436Monitor
An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to exec
HighCVSS 8.8No exploitEPSS 3%extensis · portfolioMar 1, 2022
- CVE-2022-2425236Monitor
An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute
HighCVSS 8.8No exploitEPSS 2%extensis · portfolioMar 1, 2022
- CVE-2022-2425535Monitor
Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.
HighCVSS 8.8No exploitEPSS 1%extensis · portfolioMar 1, 2022
- CVE-2022-2425135Monitor
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload funct
HighCVSS 8.8No exploitEPSS 1%extensis · portfolioMar 1, 2022
- CVE-2022-2425335Monitor
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransfe
HighCVSS 8.8No exploitEPSS 1%extensis · portfolioMar 1, 2022
- CVE-2013-394632Monitor
Heap-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a
HighCVSS 7.8No exploitEPSS 2%extensis · mrsidJan 2, 2020
- CVE-2013-394532Monitor
The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag.
HighCVSS 7.8No exploitEPSS 2%extensis · mrsidJan 2, 2020
- CVE-2017-1800624Monitor
netpub/server.np in Extensis Portfolio NetPublish has XSS in the quickfind parameter, aka Open Bug Bounty ID OBB-290447.
MediumCVSS 6.1No exploitEPSS 1%extensis · portfolio netpublishDec 31, 2017
- CVE-2005-451021Monitor
Directory traversal vulnerability in server.np in NetPublish Server 7 allows remote attackers to read arbitrary files via "../" sequences in
MediumCVSS 5.0Proof of conceptEPSS 3%extensis · netpublish serverDec 22, 2005