Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Caucho Technology

First CVE: Nov 23, 2000Active for: 26 yearsTotal CVEs: 17
34.5
VTI Score
Medium

Caucho Technology's vulnerability footprint centers on Resin, a Java application server and web container that occupies a niche but strategically important role in application deployment infrastructure. The vendor's disclosures recur around input-validation and cross-site scripting weaknesses characteristic of web-facing application servers, and vulnerabilities have a strong tendency to acquire public exploit code. Live severity, exploitation activity, and detailed exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
2.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
5.4
Avg CVSS Score
Higher Avg CVSS Score than 16% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Caucho Technology over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2000
25 years ago
Most Recent CVE
May 16, 2007
7,009 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2006-2437MEDIUM
The viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to obtain the source code for file under the web root via t
May 17, 20065.025NOYES
CVE-2007-2439HIGH
Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to cause a denial of service (device hang) and read data from a COM or LPT de
May 16, 20079.424NONO
CVE-2007-2440MEDIUM
Directory traversal vulnerability in Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to read certain files via a .. (dot dot)
May 16, 20075.023NOYES
CVE-2007-2441MEDIUM
Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to obtain the system path via certain URLs associated with (1) deploying web
May 16, 20075.023NOYES
CVE-2001-0399MEDIUM
Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request.
Jun 18, 20015.023NOYES
CVE-2001-0304MEDIUM
Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot dot) in a URL request.
May 3, 20015.023NOYES
CVE-2000-1224MEDIUM
Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, su
Nov 23, 20005.023NOYES
CVE-2003-1513MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in example scripts in Caucho Technology Resin 2.0 through 2.1.2 allow remote attackers to inject arbitrary web script or HTML vi
Dec 31, 20034.321NOYES
CVE-2006-1953HIGH
Directory traversal vulnerability in Caucho Resin 3.0.17 and 3.0.18 for Windows allows remote attackers to read arbitrary files via a "C:%5C" (encoded drive letter) in a URL.
May 17, 20067.820NONO
CVE-2001-0828MEDIUM
A cross-site scripting vulnerability in Caucho Technology Resin before 1.2.4 allows a malicious webmaster to embed Javascript in a hyperlink that ends in a .jsp extension, which ca
Dec 6, 20015.120NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
88%
12%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown17 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown17 (100.0%)
User Interaction
None0 (0.0%)
Unknown17 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown17 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
41.2% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Caucho Technology.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Caucho Technology — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Caucho Technology's Products

View all 1 CNAs →

Top CWEs