free records
7 published records for vendor free.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation3
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-290 Authentication Bypass by Spoofing1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2020-24377No exploit | A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3.free · freebox revolution firmware · CWE-20 | Critical9.6 | — | 1.2% | Sep 16, 2020 |
38Monitor | CVE-2020-24374No exploit | A DNS rebinding vulnerability in Freebox v5 before 1.5.29.free · freebox hd firmware · CWE-20 | Critical9.6 | — | 1.2% | Sep 16, 2020 |
38Monitor | CVE-2020-24376No exploit | A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2.3.free · freebox revolution firmware · CWE-20 | Critical9.6 | — | 1.0% | Sep 16, 2020 |
35Monitor | CVE-2020-24373No exploit | A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.free · freebox revolution firmware · CWE-352 | High8.8 | — | 0.5% | Sep 16, 2020 |
26Monitor | CVE-2020-24375No exploit | A DNS rebinding vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.free · freebox server · CWE-290 | Medium6.5 | — | 1.1% | Oct 19, 2020 |
26Monitor | CVE-2014-9382No exploit | Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creationfree · freebox os · CWE-352 | Medium6.5 | — | 0.8% | Jan 13, 2020 |
21Monitor | CVE-2014-9405No exploit | A Cross-Site Scripting (XSS) vulnerability exists in the description field of an Download RSS item or Contacts in Freebox OS Web interface 3free · freebox os · CWE-79 | Medium5.4 | — | 1.5% | Jan 6, 2020 |
- CVE-2020-2437738Monitor
A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3.
CriticalCVSS 9.6No exploitEPSS 1%free · freebox revolution firmwareSep 16, 2020
- CVE-2020-2437438Monitor
A DNS rebinding vulnerability in Freebox v5 before 1.5.29.
CriticalCVSS 9.6No exploitEPSS 1%free · freebox hd firmwareSep 16, 2020
- CVE-2020-2437638Monitor
A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2.3.
CriticalCVSS 9.6No exploitEPSS 1%free · freebox revolution firmwareSep 16, 2020
- CVE-2020-2437335Monitor
A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.
HighCVSS 8.8No exploitEPSS 1%free · freebox revolution firmwareSep 16, 2020
- CVE-2020-2437526Monitor
A DNS rebinding vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.
MediumCVSS 6.5No exploitEPSS 1%free · freebox serverOct 19, 2020
- CVE-2014-938226Monitor
Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation
MediumCVSS 6.5No exploitEPSS 1%free · freebox osJan 13, 2020
- CVE-2014-940521Monitor
A Cross-Site Scripting (XSS) vulnerability exists in the description field of an Download RSS item or Contacts in Freebox OS Web interface 3
MediumCVSS 5.4No exploitEPSS 2%free · freebox osJan 6, 2020