Infodrom operates a narrow product line centered on messaging and financial document-processing applications, including cfingerd and e-invoice approval systems, serving a specialized niche in the infrastructure landscape. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, while the exposure recurs through weakness classes including SQL injection, credential mishandling, and off-by-one errors that are characteristic of legacy and custom application code. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Infodrom over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0609CRITICAL Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog f | Aug 2, 2001 | 9.8 | 50 | NO | YES |
CVE-2001-0735HIGH Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute arbitrary code via a long line in the .nofinger file. | Oct 18, 2001 | 7.2 | 27 | NO | YES |
CVE-1999-0708HIGH Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field. | Sep 21, 1999 | 7.2 | 27 | NO | YES |
CVE-2023-35066CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infodrom Software E-Invoice Approval System allows SQL Injection.
This issue | Jul 25, 2023 | 9.8 | 25 | NO | NO |
CVE-2023-35067HIGH Plaintext Storage of a Password vulnerability in Infodrom Software E-Invoice Approval System allows Read Sensitive Strings Within an Executable.
This issue affects E-Invoice Appro | Jul 25, 2023 | 7.5 | 20 | NO | NO |
CVE-1999-0813HIGH Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges. | Aug 10, 1999 | 7.2 | 18 | NO | NO |
CVE-1999-0259MEDIUM cfingerd lists all users on a system via search.**@target. | May 23, 1997 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Infodrom.
Media articles that mention a CVE ID that affects a product developed by Infodrom — matched by CVE ID, not by vendor name.