Frontrange develops a focused suite of IT service management and customer relationship management products, including GoldMine, HEAT, and iHEAT, that support helpdesk and asset-tracking operations. The vulnerability signal centers on application-layer input handling, particularly SQL injection risks in web-facing and database-connected components. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Frontrange over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3642HIGH Multiple SQL injection vulnerabilities in the Call Logging feature in FrontRange HEAT 8.01 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) pas | Oct 9, 2009 | 7.5 | 28 | NO | YES |
CVE-2003-0241HIGH FrontRange GoldMine mail agent 5.70 and 6.00 before 30503 directly sends HTML to the default browser without setting its security zone or otherwise labeling it untrusted, which all | Jun 9, 2003 | 7.5 | 20 | NO | NO |
CVE-2006-2511MEDIUM The ActiveX version of FrontRange iHEAT allows remote authenticated users to run arbitrary programs or access arbitrary files on the host machine by uploading a file with an extens | May 22, 2006 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Frontrange.
Media articles that mention a CVE ID that affects a product developed by Frontrange — matched by CVE ID, not by vendor name.