Badblue is a small web server and file-sharing application characterized by a vulnerability profile centered on path-traversal and buffer-boundary weaknesses. These are input-handling and access-control defects typical of web applications with file-serving functions; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Badblue over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6377HIGH Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attackers to execute arbitrary code via a long query string. | Dec 15, 2007 | 7.5 | 74 | NO | YES |
CVE-2008-2003HIGH BadBlue 2.72 Personal Edition stores multiple programs in the web document root with insufficient access control, which allows remote attackers to (1) cause a denial of service via | Apr 28, 2008 | 7.5 | 33 | NO | NO |
CVE-2007-6378HIGH Directory traversal vulnerability in upload.dll in BadBlue 2.72b and earlier allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the filename param | Dec 15, 2007 | 7.5 | 29 | NO | YES |
CVE-2007-6379MEDIUM BadBlue 2.72b and earlier allows remote attackers to obtain sensitive information via an invalid browse parameter, which reveals the installation path in an error message. | Dec 15, 2007 | 5.0 | 23 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Badblue.
Media articles that mention a CVE ID that affects a product developed by Badblue — matched by CVE ID, not by vendor name.