Caucho Technology's vulnerability footprint centers on Resin, a Java application server and web container that occupies a niche but strategically important role in application deployment infrastructure. The vendor's disclosures recur around input-validation and cross-site scripting weaknesses characteristic of web-facing application servers, and vulnerabilities have a strong tendency to acquire public exploit code. Live severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Caucho Technology over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2437MEDIUM The viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to obtain the source code for file under the web root via t | May 17, 2006 | 5.0 | 25 | NO | YES |
CVE-2007-2439HIGH Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to cause a denial of service (device hang) and read data from a COM or LPT de | May 16, 2007 | 9.4 | 24 | NO | NO |
CVE-2007-2440MEDIUM Directory traversal vulnerability in Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to read certain files via a .. (dot dot) | May 16, 2007 | 5.0 | 23 | NO | YES |
CVE-2007-2441MEDIUM Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to obtain the system path via certain URLs associated with (1) deploying web | May 16, 2007 | 5.0 | 23 | NO | YES |
CVE-2001-0399MEDIUM Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request. | Jun 18, 2001 | 5.0 | 23 | NO | YES |
CVE-2001-0304MEDIUM Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot dot) in a URL request. | May 3, 2001 | 5.0 | 23 | NO | YES |
CVE-2000-1224MEDIUM Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, su | Nov 23, 2000 | 5.0 | 23 | NO | YES |
CVE-2003-1513MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in example scripts in Caucho Technology Resin 2.0 through 2.1.2 allow remote attackers to inject arbitrary web script or HTML vi | Dec 31, 2003 | 4.3 | 21 | NO | YES |
CVE-2006-1953HIGH Directory traversal vulnerability in Caucho Resin 3.0.17 and 3.0.18 for Windows allows remote attackers to read arbitrary files via a "C:%5C" (encoded drive letter) in a URL. | May 17, 2006 | 7.8 | 20 | NO | NO |
CVE-2001-0828MEDIUM A cross-site scripting vulnerability in Caucho Technology Resin before 1.2.4 allows a malicious webmaster to embed Javascript in a hyperlink that ends in a .jsp extension, which ca | Dec 6, 2001 | 5.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Caucho Technology.
Media articles that mention a CVE ID that affects a product developed by Caucho Technology — matched by CVE ID, not by vendor name.