Barracudanetworks develops security appliances including SSL VPN gateways and email filtering products that operate at network perimeters and inbound mail boundaries, exposing them to untrusted external traffic. The observed vulnerability signal centers on cross-site scripting issues arising from improper input neutralization in web interfaces, a pattern consistent with the web-management components common to network security devices. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Barracudanetworks over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2847HIGH img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter. | Sep 8, 2005 | 7.5 | 66 | NO | YES |
CVE-2006-4081HIGH preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote attackers to execute commands via shell metacharacters ("|" pipe symbol) in the file | Aug 11, 2006 | 7.5 | 29 | NO | YES |
CVE-2008-1094MEDIUM SQL injection vulnerability in index.cgi in the Account View page in Barracuda Spam Firewall (BSF) before 3.5.12.007 allows remote authenticated administrators to execute arbitrary | Dec 19, 2008 | 6.5 | 26 | NO | YES |
CVE-2005-2848MEDIUM Directory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to read arbitrary files via a .. (dot dot) in the | Sep 8, 2005 | 5.0 | 26 | NO | YES |
CVE-2012-4739MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Barracuda SSL VPN before 2.2.2.203 (2012-07-05) allow remote attackers to inject arbitrary web script or HTML via the (1) pol | Aug 31, 2012 | 4.3 | 25 | NO | YES |
CVE-2008-2333MEDIUM Cross-site scripting (XSS) vulnerability in ldap_test.cgi in Barracuda Spam Firewall (BSF) before 3.5.11.025 allows remote attackers to inject arbitrary web script or HTML via the | May 23, 2008 | 4.3 | 22 | NO | YES |
CVE-2006-4000MEDIUM Directory traversal vulnerability in cgi-bin/preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote authenticated users to read arbitrary fi | Aug 5, 2006 | 4.0 | 22 | NO | YES |
CVE-2007-1673HIGH unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry str | May 9, 2007 | 7.8 | 21 | NO | NO |
CVE-2006-4001HIGH Login.pm in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 contains a hard-coded password for the guest account, which allows remote attackers to read sensitive inform | Aug 5, 2006 | 7.5 | 20 | NO | NO |
CVE-2005-0431HIGH Barracuda Spam Firewall 3.1.10 and earlier does not restrict the domains that white-listed domains can send mail to, which allows members of white-listed domains to use Barracuda a | May 2, 2005 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Barracudanetworks.
Media articles that mention a CVE ID that affects a product developed by Barracudanetworks — matched by CVE ID, not by vendor name.