Sourceforge records
13 published records for vendor sourceforge.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 15.4%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-16 Configuration1
- CWE-189 Numeric Errors1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2005-4837No exploit | snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allownet-snmp · net-snmp · CWE-16 | Critical10.0 | — | 9.7% | Dec 31, 2005 |
37Monitor | CVE-2008-2503No exploit | Buffer overflow in Uploadlist in eMule X-Ray before 1.4 has unknown impact and remote attack vectors.sourceforge · emule x-ray · CWE-119 | Critical9.3 | — | 1.4% | May 29, 2008 |
31Monitor | CVE-2008-2298Proof of concept | Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1.sourceforge · web slider · CWE-287 | High7.5 | — | 2.8% | May 18, 2008 |
31Monitor | CVE-2001-0234No exploit | NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parametersourceforge · newsdaemon | High7.5 | — | 1.8% | May 3, 2001 |
28Monitor | CVE-2007-1466No exploit | Integer overflow in the WP6GeneralTextPacket::_readContents function in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allows sourceforge · wordperfect document importer-exporter · CWE-189 | Medium6.8 | — | 3.4% | Mar 16, 2007 |
27Monitor | CVE-2007-1135No exploit | Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1)sourceforge · webmplayer | Medium6.8 | — | 1.1% | Mar 2, 2007 |
27Monitor | CVE-2007-1572Proof of concept | SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 and earlier allows remote attackers to execute arbitrary SQL commands via the sourceforge · jgbbs | Medium6.8 | — | 0.8% | Mar 21, 2007 |
25Monitor | CVE-2007-6640No exploit | Creammonkey 0.9 through 1.1 and GreaseKit 1.2 through 1.3 does not properly prevent access to dangerous functions, which allows remote attacsourceforge · creammonkey · CWE-264 | Medium6.4 | — | 1.2% | Jan 3, 2008 |
24Monitor | CVE-2008-0501Proof of concept | Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a ..sourceforge · phpmyclub · CWE-22 | Medium5.8 | — | 1.9% | Jan 30, 2008 |
20Monitor | CVE-2007-1137No exploit | putmail.py in Putmail before 1.4 does not detect when a user attempts to use TLS with a server that does not support it, which causes putmaisourceforge · putmail | Medium5.0 | — | 0.9% | Mar 2, 2007 |
17Monitor | CVE-2002-2362Proof of concept | Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML sourceforge · mymarket · CWE-79 | Medium4.3 | — | 1.6% | Dec 31, 2002 |
17Monitor | CVE-2008-6161No exploit | Cross-site scripting (XSS) vulnerability in WOW Raid Manager (WRM) before 3.5.1 allows remote attackers to inject arbitrary web script or HTsourceforge · wow raid manager · CWE-79 | Medium4.3 | — | 1.0% | Feb 18, 2009 |
17Monitor | CVE-2002-2364No exploit | Cross-site scripting (XSS) vulnerability in PHP Ticket 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a sourceforge · php ticket · CWE-79 | Medium4.3 | — | 0.8% | Dec 31, 2002 |
- CVE-2005-483743Plan
snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allow
CriticalCVSS 10.0No exploitEPSS 10%net-snmp · net-snmpDec 31, 2005
- CVE-2008-250337Monitor
Buffer overflow in Uploadlist in eMule X-Ray before 1.4 has unknown impact and remote attack vectors.
CriticalCVSS 9.3No exploitEPSS 1%sourceforge · emule x-rayMay 29, 2008
- CVE-2008-229831Monitor
Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1.
HighCVSS 7.5Proof of conceptEPSS 3%sourceforge · web sliderMay 18, 2008
- CVE-2001-023431Monitor
NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter
HighCVSS 7.5No exploitEPSS 2%sourceforge · newsdaemonMay 3, 2001
- CVE-2007-146628Monitor
Integer overflow in the WP6GeneralTextPacket::_readContents function in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allows
MediumCVSS 6.8No exploitEPSS 3%sourceforge · wordperfect document importer-exporterMar 16, 2007
- CVE-2007-113527Monitor
Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1)
MediumCVSS 6.8No exploitEPSS 1%sourceforge · webmplayerMar 2, 2007
- CVE-2007-157227Monitor
SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 and earlier allows remote attackers to execute arbitrary SQL commands via the
MediumCVSS 6.8Proof of conceptEPSS 1%sourceforge · jgbbsMar 21, 2007
- CVE-2007-664025Monitor
Creammonkey 0.9 through 1.1 and GreaseKit 1.2 through 1.3 does not properly prevent access to dangerous functions, which allows remote attac
MediumCVSS 6.4No exploitEPSS 1%sourceforge · creammonkeyJan 3, 2008
- CVE-2008-050124Monitor
Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a ..
MediumCVSS 5.8Proof of conceptEPSS 2%sourceforge · phpmyclubJan 30, 2008
- CVE-2007-113720Monitor
putmail.py in Putmail before 1.4 does not detect when a user attempts to use TLS with a server that does not support it, which causes putmai
MediumCVSS 5.0No exploitEPSS 1%sourceforge · putmailMar 2, 2007
- CVE-2002-236217Monitor
Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML
MediumCVSS 4.3Proof of conceptEPSS 2%sourceforge · mymarketDec 31, 2002
- CVE-2008-616117Monitor
Cross-site scripting (XSS) vulnerability in WOW Raid Manager (WRM) before 3.5.1 allows remote attackers to inject arbitrary web script or HT
MediumCVSS 4.3No exploitEPSS 1%sourceforge · wow raid managerFeb 18, 2009
- CVE-2002-236417Monitor
Cross-site scripting (XSS) vulnerability in PHP Ticket 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a
MediumCVSS 4.3No exploitEPSS 1%sourceforge · php ticketDec 31, 2002