surfcontrol records
12 published records for vendor surfcontrol.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
All records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2002-0705No exploit | The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directorysurfcontrol · superscout web filter | High7.5 | — | 2.5% | Oct 10, 2002 |
30Monitor | CVE-2002-0709Proof of concept | SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to execute arbitrary SQLsurfcontrol · superscout web filter | High7.5 | — | 1.1% | Oct 10, 2002 |
30Monitor | CVE-2002-0706No exploit | UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allowssurfcontrol · superscout web filter | High7.5 | — | 1.0% | Oct 10, 2002 |
22Monitor | CVE-2002-1530Proof of concept | The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwordssurfcontrol · superscout email filter | Medium5.0 | — | 5.9% | Mar 31, 2003 |
21Monitor | CVE-2002-0708Proof of concept | Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary fsurfcontrol · superscout web filter | Medium5.0 | — | 3.5% | Oct 10, 2002 |
21Monitor | CVE-2002-2121No exploit | SurfControl SuperScout Email filter for SMTP 3.5.1 allows remote attackers to cause a denial of service (crash) via a long SMTP (1) HELO or surfcontrol · superscout email filter | Medium5.0 | — | 2.6% | Dec 31, 2002 |
21Monitor | CVE-2002-1531No exploit | The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (crsurfcontrol · superscout email filter | Medium5.0 | — | 2.6% | Mar 31, 2003 |
21Monitor | CVE-2002-1532No exploit | The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (resurfcontrol · superscout email filter | Medium5.0 | — | 2.6% | Mar 31, 2003 |
21Monitor | CVE-2002-0707No exploit | The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via largesurfcontrol · superscout web filter | Medium5.0 | — | 1.8% | Oct 10, 2002 |
18Monitor | CVE-2002-1529Proof of concept | Cross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl SuperScout Email Fisurfcontrol · superscout email filter | Medium4.3 | — | 3.6% | Mar 31, 2003 |
18Monitor | CVE-2001-1465No exploit | SurfControl SuperScout only filters packets containing both an HTTP GET request and a Host header, which allows local users to bypass filtersurfcontrol · superscout web filter | Medium4.6 | — | 0.4% | Feb 26, 2002 |
8Monitor | CVE-2000-0124No exploit | surfCONTROL SuperScout does not properly asign a category to web sites with a .surfcontrol · superscout | Low2.1 | — | 0.4% | Feb 3, 2000 |
- CVE-2002-070531Monitor
The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directory
HighCVSS 7.5No exploitEPSS 2%surfcontrol · superscout web filterOct 10, 2002
- CVE-2002-070930Monitor
SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to execute arbitrary SQL
HighCVSS 7.5Proof of conceptEPSS 1%surfcontrol · superscout web filterOct 10, 2002
- CVE-2002-070630Monitor
UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows
HighCVSS 7.5No exploitEPSS 1%surfcontrol · superscout web filterOct 10, 2002
- CVE-2002-153022Monitor
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords
MediumCVSS 5.0Proof of conceptEPSS 6%surfcontrol · superscout email filterMar 31, 2003
- CVE-2002-070821Monitor
Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary f
MediumCVSS 5.0Proof of conceptEPSS 3%surfcontrol · superscout web filterOct 10, 2002
- CVE-2002-212121Monitor
SurfControl SuperScout Email filter for SMTP 3.5.1 allows remote attackers to cause a denial of service (crash) via a long SMTP (1) HELO or
MediumCVSS 5.0No exploitEPSS 3%surfcontrol · superscout email filterDec 31, 2002
- CVE-2002-153121Monitor
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (cr
MediumCVSS 5.0No exploitEPSS 3%surfcontrol · superscout email filterMar 31, 2003
- CVE-2002-153221Monitor
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (re
MediumCVSS 5.0No exploitEPSS 3%surfcontrol · superscout email filterMar 31, 2003
- CVE-2002-070721Monitor
The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via large
MediumCVSS 5.0No exploitEPSS 2%surfcontrol · superscout web filterOct 10, 2002
- CVE-2002-152918Monitor
Cross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl SuperScout Email Fi
MediumCVSS 4.3Proof of conceptEPSS 4%surfcontrol · superscout email filterMar 31, 2003
- CVE-2001-146518Monitor
SurfControl SuperScout only filters packets containing both an HTTP GET request and a Host header, which allows local users to bypass filter
MediumCVSS 4.6No exploitEPSS 0%surfcontrol · superscout web filterFeb 26, 2002
- CVE-2000-01248Monitor
surfCONTROL SuperScout does not properly asign a category to web sites with a .
LowCVSS 2.1No exploitEPSS 0%surfcontrol · superscoutFeb 3, 2000