Analogx develops a focused line of lightweight server and networking utilities, including its SimpleServer HTTP server, proxy, and Shout audio streaming products, which occupy a niche but persistent position in the vulnerability landscape. The vendor's disclosures center on path-traversal and directory-restriction weaknesses characteristic of file-serving and request-routing components, and public exploit code has frequently been associated with these flaws. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Analogx over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-1586HIGH Directory traversal vulnerability in SimpleServer:WWW 1.13 and earlier allows remote attackers to execute arbitrary programs via encoded ../ ("%2E%2E%2F%") sequences in a request t | Feb 12, 2010 | 10.0 | 38 | NO | YES |
CVE-2002-0968HIGH Buffer overflow in AnalogX SimpleServer:WWW 1.16 and earlier allows remote attackers to cause a denial of service (crash) and execute code via a long HTTP request method name. | Oct 4, 2002 | 7.5 | 37 | NO | YES |
CVE-2002-1001HIGH Buffer overflows in AnalogX Proxy before 4.12 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long HTTP request to TCP port 6588 | Oct 4, 2002 | 7.5 | 36 | NO | YES |
CVE-2000-0011HIGH Buffer overflow in AnalogX SimpleServer:WWW HTTP server allows remote attackers to execute commands via a long GET request. | Dec 31, 1999 | 7.5 | 32 | NO | YES |
CVE-2000-0473HIGH Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET request for a program in the cgi-bin directory. | Jun 15, 2000 | 7.5 | 30 | NO | YES |
CVE-2001-0386MEDIUM AnalogX SimpleServer:WWW 1.08 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory. | Jul 2, 2001 | 5.0 | 28 | NO | YES |
CVE-2003-0410HIGH Buffer overflow in AnalogX Proxy 4.13 allows remote attackers to execute arbitrary code via a long URL to port 6588. | Jun 30, 2003 | 10.0 | 27 | NO | NO |
CVE-2000-0656MEDIUM Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the FTP protocol. | Jul 25, 2000 | 5.0 | 26 | NO | YES |
CVE-2000-0664MEDIUM AnalogX SimpleServer:WWW 1.06 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack that uses the %2E URL encoding for the dots. | Jul 26, 2000 | 5.0 | 25 | NO | YES |
CVE-2000-0243MEDIUM AnalogX SimpleServer:WWW HTTP server 1.03 allows remote attackers to cause a denial of service via a short GET request to cgi-bin. | Mar 25, 2000 | 5.0 | 25 | NO | YES |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Analogx.
Media articles that mention a CVE ID that affects a product developed by Analogx — matched by CVE ID, not by vendor name.