Feng is a narrowly scoped vendor with a single product of the same name that maintains elevated prominence in the vulnerability landscape despite a very small disclosure volume. The observed vulnerabilities center on memory-safety and bounds-checking issues, reflecting the low-level implementation demands of the product. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Feng over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6630MEDIUM The Url_init function in utils/url.c in Netembryo 0.0.4, when used by LScube Feng, allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a ma | Jan 4, 2008 | 5.0 | 23 | NO | YES |
CVE-2007-6626HIGH Multiple buffer overflows in the RTSP_valid_response_msg function in RTSP_state_machine.c in LScube Feng 0.1.15 and earlier allow remote attackers to execute arbitrary code via (1) | Jan 4, 2008 | 7.5 | 20 | NO | NO |
CVE-2007-6627HIGH Integer overflow in the RTSP_remove_msg function in RTSP_lowlevel.c in LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (crash) and possibly exec | Jan 4, 2008 | 7.5 | 20 | NO | NO |
CVE-2007-6628MEDIUM LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via (1) a malformed Transport header, which triggers mispars | Jan 4, 2008 | 5.0 | 15 | NO | NO |
CVE-2007-6629MEDIUM Interpretation conflict in LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a User-Agent header line that | Jan 4, 2008 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Feng.
Media articles that mention a CVE ID that affects a product developed by Feng — matched by CVE ID, not by vendor name.