Icewall File Manager
Vendor:
First CVE: Sep 23, 2013 · Active for 12 years
14
Total CVEs
More Total CVEs than 92% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Icewall File Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 23, 2013
12 years ago
Most Recent CVE
Jul 30, 2018
2,920 days ago
CVE Severity & Scoring
Icewall File Manager14 CVEs
64%
29%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network3 (21.4%)
Unknown11 (78.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (21.4%)
High0 (0.0%)
Unknown11 (78.6%)
User Interaction
None3 (21.4%)
Unknown11 (78.6%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (21.4%)
Unknown11 (78.6%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-3627HIGH The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recu | May 17, 2016 | 7.5 | 30 | NO | NO |
CVE-2016-3705HIGH The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependen | May 17, 2016 | 7.5 | 27 | NO | NO |
CVE-2016-9597HIGH It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a De | Jul 30, 2018 | 7.5 | 21 | NO | NO |
CVE-2015-5312HIGH The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial o | Dec 15, 2015 | 7.1 | 20 | NO | NO |
CVE-2015-8241MEDIUM The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and | Dec 15, 2015 | 6.4 | 19 | NO | NO |
CVE-2015-7942MEDIUM The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent att | Nov 18, 2015 | 6.8 | 19 | NO | NO |
CVE-2015-7500MEDIUM The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors rela | Dec 15, 2015 | 5.0 | 18 | NO | NO |
CVE-2015-8317MEDIUM The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) in | Dec 15, 2015 | 5.0 | 17 | NO | NO |
CVE-2015-8242MEDIUM The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based | Dec 15, 2015 | 5.8 | 17 | NO | NO |
CVE-2015-7499MEDIUM Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspeci | Dec 15, 2015 | 5.0 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Icewall File Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0 | 14 | 5.0 | 4.2% | 0 | 0 |