Icewall File Manager

Vendor:

First CVE: Sep 23, 2013 · Active for 12 years

14
Total CVEs
More Total CVEs than 92% of tracked products
3.5
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Icewall File Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 23, 2013
12 years ago
Most Recent CVE
Jul 30, 2018
2,920 days ago

CVE Severity & Scoring

Icewall File Manager14 CVEs
All CVEs353,173 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network3 (21.4%)
Unknown11 (78.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (21.4%)
High0 (0.0%)
Unknown11 (78.6%)
User Interaction
None3 (21.4%)
Unknown11 (78.6%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (21.4%)
Unknown11 (78.6%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recu
May 17, 20167.530NONO
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependen
May 17, 20167.527NONO
It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a De
Jul 30, 20187.521NONO
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial o
Dec 15, 20157.120NONO
The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and
Dec 15, 20156.419NONO
The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent att
Nov 18, 20156.819NONO
The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors rela
Dec 15, 20155.018NONO
The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) in
Dec 15, 20155.017NONO
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based
Dec 15, 20155.817NONO
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspeci
Dec 15, 20155.017NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Icewall File Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.0145.04.2%00