Записи viewvc
21 опубликованных записей вендора viewvc.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 61,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
- CWE-399 Resource Management Errors1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2010-0005Эксплойта нет | query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, whiviewvc · viewvc · CWE-264 | Высокая7,5 | — | 1,7 % | 29 янв. 2010 г. |
30Наблюдать | CVE-2007-5743Эксплойта нет | viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.viewvc · viewvc · CWE-732 | Высокая7,5 | — | 1,1 % | 7 нояб. 2019 г. |
30Наблюдать | CVE-2025-54141Эксплойта нет | ViewVC's standalone server exposes arbitrary server filesystem contentviewvc · viewvc · CWE-22 | Высокая7,5 | — | 0,9 % | 22 июл. 2025 г. |
27Наблюдать | CVE-2006-5442Эксплойта нет | ViewVC 1.0.2 and earlier does not specify a charset in its HTTP headers or HTML documents, which allows remote attackers to conduct cross-siviewvc · viewvc | Средняя6,8 | — | 1,5 % | 20 окт. 2006 г. |
24Наблюдать | CVE-2017-5938Эксплойта нет | Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows reviewvc · viewvc · CWE-79 | Средняя6,1 | — | 1,3 % | 15 мар. 2017 г. |
24Наблюдать | CVE-2023-22456Эксплойта нет | ViewVC XSS vulnerability in revision view changed pathsviewvc · viewvc · CWE-79 | Средняя6,1 | — | 0,7 % | 3 янв. 2023 г. |
23Наблюдать | CVE-2008-4325Эксплойта нет | lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which alviewvc · viewvc | Средняя5,8 | — | 1,4 % | 30 сент. 2008 г. |
21Наблюдать | CVE-2009-5024Эксплойта нет | ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumptviewvc · viewvc · CWE-399 | Средняя5,0 | — | 2,6 % | 23 мая 2011 г. |
21Наблюдать | CVE-2010-0004Эксплойта нет | ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discoveviewvc · viewvc · CWE-200 | Средняя5,0 | — | 2,6 % | 29 янв. 2010 г. |
21Наблюдать | CVE-2012-3356Эксплойта нет | The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows rviewvc · viewvc · CWE-287 | Средняя5,0 | — | 2,0 % | 22 июл. 2012 г. |
21Наблюдать | CVE-2012-3357Эксплойта нет | The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is copviewvc · viewvc · CWE-200 | Средняя5,0 | — | 1,9 % | 22 июл. 2012 г. |
21Наблюдать | CVE-2009-3619Эксплойта нет | Unspecified vulnerability in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 has unknown impact and remote attack vectors related to "printing viewvc · viewvc | Средняя5,0 | — | 1,8 % | 9 нояб. 2009 г. |
21Наблюдать | CVE-2023-22464Эксплойта нет | ViewVC XSS vulnerability in revision view changed path "copyfrom" locationsviewvc · viewvc · CWE-79 | Средняя5,4 | — | 0,6 % | 4 янв. 2023 г. |
18Наблюдать | CVE-2012-4533Эксплойта нет | Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before viewvc · viewvc · CWE-79 | Средняя4,3 | — | 3,1 % | 18 нояб. 2012 г. |
18Наблюдать | CVE-2010-0736Эксплойта нет | Cross-site scripting (XSS) vulnerability in the view_queryform function in lib/viewvc.py in ViewVC before 1.0.10, and 1.1.x before 1.1.4, alviewvc · viewvc · CWE-79 | Средняя4,3 | — | 1,7 % | 19 мар. 2010 г. |
17Наблюдать | CVE-2009-3618Эксплойта нет | Cross-site scripting (XSS) vulnerability in viewvc.py in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 allows remote attackers to inject arbiviewvc · viewvc · CWE-79 | Средняя4,3 | — | 1,6 % | 9 нояб. 2009 г. |
17Наблюдать | CVE-2008-1291Эксплойта нет | ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read viewvc · viewvc · CWE-200 | Средняя4,3 | — | 1,4 % | 24 мар. 2008 г. |
17Наблюдать | CVE-2008-1290Эксплойта нет | ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote attaviewvc · viewvc · CWE-200 | Средняя4,3 | — | 1,4 % | 24 мар. 2008 г. |
17Наблюдать | CVE-2008-1292Эксплойта нет | ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtaiviewvc · viewvc · CWE-200 | Средняя4,3 | — | 1,4 % | 24 мар. 2008 г. |
14Наблюдать | CVE-2020-5283Эксплойта нет | XSS vulnerability in CVS show_subdir_lastmod supportviewvc · viewvc · CWE-80 | Низкая3,5 | — | 1,2 % | 2 апр. 2020 г. |
11Наблюдать | CVE-2010-0132Эксплойта нет | Cross-site scripting (XSS) vulnerability in ViewVC 1.1 before 1.1.5 and 1.0 before 1.0.11, when the regular expression search functionality viewvc · viewvc · CWE-79 | Низкая2,6 | — | 2,3 % | 31 мар. 2010 г. |
- CVE-2010-000531Наблюдать
query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, whi
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %viewvc · viewvc29 янв. 2010 г.
- CVE-2007-574330Наблюдать
viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %viewvc · viewvc7 нояб. 2019 г.
- CVE-2025-5414130Наблюдать
ViewVC's standalone server exposes arbitrary server filesystem content
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %viewvc · viewvc22 июл. 2025 г.
- CVE-2006-544227Наблюдать
ViewVC 1.0.2 and earlier does not specify a charset in its HTTP headers or HTML documents, which allows remote attackers to conduct cross-si
СредняяCVSS 6,8Эксплойта нетEPSS 2 %viewvc · viewvc20 окт. 2006 г.
- CVE-2017-593824Наблюдать
Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows re
СредняяCVSS 6,1Эксплойта нетEPSS 1 %viewvc · viewvc15 мар. 2017 г.
- CVE-2023-2245624Наблюдать
ViewVC XSS vulnerability in revision view changed paths
СредняяCVSS 6,1Эксплойта нетEPSS 1 %viewvc · viewvc3 янв. 2023 г.
- CVE-2008-432523Наблюдать
lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which al
СредняяCVSS 5,8Эксплойта нетEPSS 1 %viewvc · viewvc30 сент. 2008 г.
- CVE-2009-502421Наблюдать
ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumpt
СредняяCVSS 5,0Эксплойта нетEPSS 3 %viewvc · viewvc23 мая 2011 г.
- CVE-2010-000421Наблюдать
ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discove
СредняяCVSS 5,0Эксплойта нетEPSS 3 %viewvc · viewvc29 янв. 2010 г.
- CVE-2012-335621Наблюдать
The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows r
СредняяCVSS 5,0Эксплойта нетEPSS 2 %viewvc · viewvc22 июл. 2012 г.
- CVE-2012-335721Наблюдать
The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is cop
СредняяCVSS 5,0Эксплойта нетEPSS 2 %viewvc · viewvc22 июл. 2012 г.
- CVE-2009-361921Наблюдать
Unspecified vulnerability in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 has unknown impact and remote attack vectors related to "printing
СредняяCVSS 5,0Эксплойта нетEPSS 2 %viewvc · viewvc9 нояб. 2009 г.
- CVE-2023-2246421Наблюдать
ViewVC XSS vulnerability in revision view changed path "copyfrom" locations
СредняяCVSS 5,4Эксплойта нетEPSS 1 %viewvc · viewvc4 янв. 2023 г.
- CVE-2012-453318Наблюдать
Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before
СредняяCVSS 4,3Эксплойта нетEPSS 3 %viewvc · viewvc18 нояб. 2012 г.
- CVE-2010-073618Наблюдать
Cross-site scripting (XSS) vulnerability in the view_queryform function in lib/viewvc.py in ViewVC before 1.0.10, and 1.1.x before 1.1.4, al
СредняяCVSS 4,3Эксплойта нетEPSS 2 %viewvc · viewvc19 мар. 2010 г.
- CVE-2009-361817Наблюдать
Cross-site scripting (XSS) vulnerability in viewvc.py in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 allows remote attackers to inject arbi
СредняяCVSS 4,3Эксплойта нетEPSS 2 %viewvc · viewvc9 нояб. 2009 г.
- CVE-2008-129117Наблюдать
ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read
СредняяCVSS 4,3Эксплойта нетEPSS 1 %viewvc · viewvc24 мар. 2008 г.
- CVE-2008-129017Наблюдать
ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote atta
СредняяCVSS 4,3Эксплойта нетEPSS 1 %viewvc · viewvc24 мар. 2008 г.
- CVE-2008-129217Наблюдать
ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtai
СредняяCVSS 4,3Эксплойта нетEPSS 1 %viewvc · viewvc24 мар. 2008 г.
- CVE-2020-528314Наблюдать
XSS vulnerability in CVS show_subdir_lastmod support
НизкаяCVSS 3,5Эксплойта нетEPSS 1 %viewvc · viewvc2 апр. 2020 г.
- CVE-2010-013211Наблюдать
Cross-site scripting (XSS) vulnerability in ViewVC 1.1 before 1.1.5 and 1.0 before 1.0.11, when the regular expression search functionality
НизкаяCVSS 2,6Эксплойта нетEPSS 2 %viewvc · viewvc31 мар. 2010 г.