Evolvable Corporation operates a narrowly scoped product portfolio centered on the Shambala Server, which appears to address a specialized infrastructure or application-serving role. The vendor's vulnerability disclosures carry NVD classification as general or miscellaneous weakness categories, suggesting either a lack of precise categorization detail or vulnerabilities that do not fit established weakness taxonomy; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Evolvable Corporation over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0876MEDIUM Web server for Shambala 4.5 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request. | Oct 4, 2002 | 5.0 | 26 | NO | YES |
CVE-2001-0758HIGH Directory traversal vulnerability in Shambala 4.5 allows remote attackers to escape the FTP root directory via "CWD ..." command. | Oct 18, 2001 | 7.5 | 26 | NO | NO |
CVE-2000-0954HIGH Shambala Server 4.5 stores passwords in plaintext, which could allow local users to obtain the passwords and compromise the server. | Dec 19, 2000 | 10.0 | 25 | NO | NO |
CVE-2000-0953MEDIUM Shambala Server 4.5 allows remote attackers to cause a denial of service by opening then closing a connection. | Dec 19, 2000 | 5.0 | 23 | NO | YES |
CVE-2002-0877MEDIUM Directory traversal vulnerability in the FTP server for Shambala 4.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) LIST (ls) or (2) GET commands. | Oct 4, 2002 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Evolvable Corporation.
Media articles that mention a CVE ID that affects a product developed by Evolvable Corporation — matched by CVE ID, not by vendor name.