Search Appliance
Vendor:
First CVE: Nov 22, 2005 · Active for 20 years
7
Total CVEs
More Total CVEs than 85% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
5.0
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Search Appliance over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 22, 2005
20 years ago
Most Recent CVE
Jul 28, 2011
5,479 days ago
CVE Severity & Scoring
Search Appliance7 CVEs
86%
14%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown7 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown7 (100.0%)
User Interaction
None0 (0.0%)
Unknown7 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown7 (100.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-3757HIGH The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to obtain sensitive information and execute arbitrary code via | Nov 22, 2005 | 7.5 | 59 | NO | YES |
CVE-2005-3758MEDIUM Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly | Nov 22, 2005 | 4.3 | 20 | NO | NO |
CVE-2011-1339MEDIUM Cross-site scripting (XSS) vulnerability in Google Search Appliance before 5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Jul 28, 2011 | 4.3 | 16 | NO | NO |
CVE-2005-3755MEDIUM Directory traversal vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to determine the existence of arbitrary files via a | Nov 22, 2005 | 5.0 | 16 | NO | NO |
CVE-2006-6223MEDIUM Cross-site scripting (XSS) vulnerability in Google Search Appliance and Google Mini allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded q parameter. | Dec 2, 2006 | 4.3 | 15 | NO | NO |
CVE-2005-3756MEDIUM Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to port scan arbitrary hosts via URLs with modified targets and ports, then comparing th | Nov 22, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-3754MEDIUM Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly | Nov 22, 2005 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
14.3% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
14.3% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Search Appliance
Top CWEs
Versions
No cataloged versions.