The Ipip Project maintains a narrowly scoped IP geolocation and network intelligence product where vulnerabilities have centered on data-protection mechanisms. The recurring exposure reflects gaps in encryption of sensitive information handled by the product. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ipip Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10673HIGH ipip-coffee queries geolocation information from IP ipip-coffee downloads geolocation resources over HTTP, which leaves it vulnerable to MITM attacks. This could impact the integri | Jun 4, 2018 | 8.1 | 22 | NO | NO |
CVE-2016-10594HIGH ipip is a Node.js module to query geolocation information for an IP or domain, based on database by ipip.net. ipip downloads data resources over HTTP, which leaves it vulnerable to | Jun 1, 2018 | 8.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ipip Project.
Media articles that mention a CVE ID that affects a product developed by Ipip Project — matched by CVE ID, not by vendor name.