Resin

Vendor:

First CVE: Nov 23, 2004 · Active for 21 years

10
Total CVEs
More Total CVEs than 89% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Resin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2004
21 years ago
Most Recent CVE
Apr 4, 2022
1,576 days ago

CVE Severity & Scoring

Resin10 CVEs
All CVEs353,240 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (10.0%)
Unknown9 (90.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (10.0%)
High0 (0.0%)
Unknown9 (90.0%)
User Interaction
None1 (10.0%)
Unknown9 (90.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (10.0%)
Unknown9 (90.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ;
Apr 4, 20227.542NOYES
Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP request for "WEB-INF..", which is
Nov 23, 20045.026NOYES
Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possibly other versions allow remote
May 24, 20104.325NOYES
Caucho Quercus, as distributed in Resin before 4.0.29, does not properly implement the == (equals sign equals sign) operator for comparisons, which has unspecified impact and conte
Aug 12, 20127.523NONO
Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to bypass intended restrictions on filename extensions for created files via a %00 sequence in a path
Aug 12, 20126.422NONO
Caucho Quercus, as distributed in Resin before 4.0.29, overwrites entries in the SERVER superglobal array on the basis of POST parameters, which has unspecified impact and remote a
Aug 12, 20127.522NONO
Caucho Quercus, as distributed in Resin before 4.0.29, does not properly handle unspecified characters in the names of variables, which has unknown impact and remote attack vectors
Aug 12, 20127.522NONO
Directory traversal vulnerability in Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to create files in arbitrary directories via a .. (dot dot) in a
Aug 12, 20125.019NONO
The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted
Jul 26, 20145.015NONO
Cross-site scripting (XSS) vulnerability in the viewfile documentation command in Caucho Resin before 3.0.25, and 3.1.x before 3.1.4, allows remote attackers to inject arbitrary we
Jun 30, 20084.314NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
10.0% of CVEs· 97th percentile
ExploitDB
2 CVEs
20.0% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Resin

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.0.956.82.4%00
4.0.856.82.4%00
4.0.756.82.4%00
4.0.666.42.5%01
4.0.556.82.4%00
4.0.456.82.4%00
4.0.3815.01.7%00
4.0.3715.01.7%00
4.0.3615.01.7%00
4.0.356.82.4%00
4.0.2756.82.4%00
4.0.2656.82.4%00
4.0.2556.82.4%00
4.0.2456.82.4%00
4.0.2356.82.4%00
4.0.2256.82.4%00
4.0.2156.82.4%00
4.0.2056.82.4%00
4.0.256.82.4%00
4.0.1956.82.4%00