Imatix develops a niche web server and application platform historically represented by Xitami, which despite a narrow product scope acquired public exploit tooling for its disclosed vulnerabilities. The vendor's exposure recurs through memory-safety and format-string weaknesses characteristic of older native-code server implementations. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Imatix over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-5067HIGH Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long If-Modified-Since header to (1) xigui32.exe or (2) xitami.ex | Sep 24, 2007 | 7.5 | 76 | NO | YES |
CVE-2008-6519HIGH Format string vulnerability in Xitami Web Server 2.2a through 2.5c2, and possibly other versions, allows remote attackers to cause a denial of service (daemon crash) and possibly e | Mar 25, 2009 | 10.0 | 37 | NO | YES |
CVE-2008-6520HIGH Multiple format string vulnerabilities in the SSI filter in Xitami Web Server 2.5c2, and possibly other versions, allow remote attackers to cause a denial of service (daemon crash) | Mar 25, 2009 | 10.0 | 26 | NO | NO |
CVE-2002-1965MEDIUM Cross-site scripting (XSS) vulnerability in Errors.gsl in Imatix Xitami 2.5b4 and 2.5b5 allows remote attackers to inject arbitrary web script or HTML via the (1) Javascript events | Dec 31, 2002 | 4.3 | 26 | NO | YES |
CVE-2002-1942MEDIUM Imatix Xitami 2.5 b5 does not properly terminate certain Keep-Alive connections that have been broken or closed early, which allows remote attackers to cause a denial of service (c | Dec 31, 2002 | 5.0 | 15 | NO | NO |
CVE-2001-0391MEDIUM Xitami 2.5d4 and earlier allows remote attackers to crash the server via an HTTP request to the /aux directory. | Jul 2, 2001 | 5.0 | 15 | NO | NO |
CVE-2000-1225MEDIUM Xitami 2.5b installs the testcgi.exe program by default in the cgi-bin directory, which allows remote attackers to gain sensitive configuration information about the web server by | Dec 31, 2000 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Imatix.
Media articles that mention a CVE ID that affects a product developed by Imatix — matched by CVE ID, not by vendor name.