Перейти к содержимому
Noroxi

Записи viewvc

21 опубликованных записей вендора viewvc.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
61,9 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

21 записей
  • CVE-2010-0005
    31Наблюдать

    query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, whi

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    viewvc · viewvc29 янв. 2010 г.

  • CVE-2007-5743
    30Наблюдать

    viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    viewvc · viewvc7 нояб. 2019 г.

  • CVE-2025-54141
    30Наблюдать

    ViewVC's standalone server exposes arbitrary server filesystem content

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    viewvc · viewvc22 июл. 2025 г.

  • CVE-2006-5442
    27Наблюдать

    ViewVC 1.0.2 and earlier does not specify a charset in its HTTP headers or HTML documents, which allows remote attackers to conduct cross-si

    СредняяCVSS 6,8Эксплойта нетEPSS 2 %

    viewvc · viewvc20 окт. 2006 г.

  • CVE-2017-5938
    24Наблюдать

    Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows re

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    viewvc · viewvc15 мар. 2017 г.

  • CVE-2023-22456
    24Наблюдать

    ViewVC XSS vulnerability in revision view changed paths

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    viewvc · viewvc3 янв. 2023 г.

  • CVE-2008-4325
    23Наблюдать

    lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which al

    СредняяCVSS 5,8Эксплойта нетEPSS 1 %

    viewvc · viewvc30 сент. 2008 г.

  • CVE-2009-5024
    21Наблюдать

    ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumpt

    СредняяCVSS 5,0Эксплойта нетEPSS 3 %

    viewvc · viewvc23 мая 2011 г.

  • CVE-2010-0004
    21Наблюдать

    ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discove

    СредняяCVSS 5,0Эксплойта нетEPSS 3 %

    viewvc · viewvc29 янв. 2010 г.

  • CVE-2012-3356
    21Наблюдать

    The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows r

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    viewvc · viewvc22 июл. 2012 г.

  • CVE-2012-3357
    21Наблюдать

    The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is cop

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    viewvc · viewvc22 июл. 2012 г.

  • CVE-2009-3619
    21Наблюдать

    Unspecified vulnerability in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 has unknown impact and remote attack vectors related to "printing

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    viewvc · viewvc9 нояб. 2009 г.

  • CVE-2023-22464
    21Наблюдать

    ViewVC XSS vulnerability in revision view changed path "copyfrom" locations

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    viewvc · viewvc4 янв. 2023 г.

  • CVE-2012-4533
    18Наблюдать

    Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before

    СредняяCVSS 4,3Эксплойта нетEPSS 3 %

    viewvc · viewvc18 нояб. 2012 г.

  • CVE-2010-0736
    18Наблюдать

    Cross-site scripting (XSS) vulnerability in the view_queryform function in lib/viewvc.py in ViewVC before 1.0.10, and 1.1.x before 1.1.4, al

    СредняяCVSS 4,3Эксплойта нетEPSS 2 %

    viewvc · viewvc19 мар. 2010 г.

  • CVE-2009-3618
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in viewvc.py in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 allows remote attackers to inject arbi

    СредняяCVSS 4,3Эксплойта нетEPSS 2 %

    viewvc · viewvc9 нояб. 2009 г.

  • CVE-2008-1291
    17Наблюдать

    ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    viewvc · viewvc24 мар. 2008 г.

  • CVE-2008-1290
    17Наблюдать

    ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote atta

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    viewvc · viewvc24 мар. 2008 г.

  • CVE-2008-1292
    17Наблюдать

    ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtai

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    viewvc · viewvc24 мар. 2008 г.

  • CVE-2020-5283
    14Наблюдать

    XSS vulnerability in CVS show_subdir_lastmod support

    НизкаяCVSS 3,5Эксплойта нетEPSS 1 %

    viewvc · viewvc2 апр. 2020 г.

  • CVE-2010-0132
    11Наблюдать

    Cross-site scripting (XSS) vulnerability in ViewVC 1.1 before 1.1.5 and 1.0 before 1.0.11, when the regular expression search functionality

    НизкаяCVSS 2,6Эксплойта нетEPSS 2 %

    viewvc · viewvc31 мар. 2010 г.