Critical Path produced directory-server and content-management products that operated in enterprise messaging and collaboration environments, with the modest vulnerability signal centered on these systems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Critical Path over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0787HIGH Cross-site scripting vulnerabilities in iCon administrative web server for Critical Path inJoin Directory Server 4.0 allow remote attackers to execute script as the administrator v | Aug 12, 2002 | 7.5 | 29 | NO | YES |
CVE-2002-0786MEDIUM iCon administrative web server for Critical Path inJoin Directory Server 4.0 allows authenticated inJoin administrators to read arbitrary files by specifying the target file in the | Aug 12, 2002 | 5.0 | 23 | NO | YES |
CVE-2001-1314HIGH Buffer overflows in Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrar | Jul 16, 2001 | 7.5 | 21 | NO | NO |
CVE-2001-1315HIGH Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed | Jul 16, 2001 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Critical Path.
Media articles that mention a CVE ID that affects a product developed by Critical Path — matched by CVE ID, not by vendor name.