Frox is a niche proxy and firewall application with a narrowly scoped vulnerability footprint centered on its primary product. The observed weakness classes appear generically classified, limiting structural inference about recurring exposure patterns; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Frox over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2807HIGH frox 0.7.18, when running setuid root, does not properly drop privileges when reading a configuration file, which allows local users to read portions of arbitrary files via the -f | Sep 7, 2005 | 7.2 | 27 | NO | YES |
CVE-2005-2808HIGH frox 0.7.16 and 0.7.17 does not properly parse certain Deny ACLs, which might allow attackers to bypass intended restrictions and access blocked hosts. | Sep 7, 2005 | 7.5 | 22 | NO | NO |
CVE-2001-0936HIGH Buffer overflow in Frox transparent FTP proxy 0.6.6 and earlier, with the local caching method selected, allows remote FTP servers to run arbitrary code via a long response to an M | Nov 30, 2001 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Frox.
Media articles that mention a CVE ID that affects a product developed by Frox — matched by CVE ID, not by vendor name.