Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Iplanet

First CVE: Feb 23, 2000Active for: 26 yearsTotal CVEs: 17
33.5
VTI Score
Medium

Iplanet's vulnerability profile centers on a legacy suite of web and application server products that were widely deployed in enterprise environments, including its web server, calendar server, and enterprise server platforms. The durable signal reflects the vendor's web-facing infrastructure role, with recurrent weaknesses including cross-site scripting and input-handling issues characteristic of server-side web applications, alongside a moderate tendency toward public exploit availability. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Iplanet over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 23, 2000
26 years ago
Most Recent CVE
Feb 5, 2010
6,014 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2001-0746HIGH
Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code v
Oct 18, 200110.042NOYES
CVE-2002-0845HIGH
Buffer overflow in Sun ONE / iPlanet Web Server 4.1 and 6.0 allows remote attackers to execute arbitrary code via an HTTP request using chunked transfer encoding.
Aug 12, 20027.530NONO
CVE-2001-0431HIGH
Vulnerability in iPlanet Web Server Enterprise Edition 4.x.
Jul 2, 200110.027NONO
CVE-2002-0686HIGH
Buffer overflow in the search component for iPlanet Web Server (iWS) 4.1 and Sun ONE Web Server 6.0 allows remote attackers to execute arbitrary code via a long argument to the NS-
Jul 23, 20027.525NONO
CVE-2001-0747HIGH
Buffer overflow in iPlanet Web Server (iWS) Enterprise Edition 4.1, service packs 3 through 7, allows remote attackers to cause a denial of service and possibly execute arbitrary c
Oct 18, 20017.525NONO
CVE-2000-1077HIGH
Buffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote attackers to execute arbitrary commands via a long filename with a .shtml extension.
Dec 11, 200010.025NONO
CVE-2002-1316MEDIUM
importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and
Nov 29, 20026.823NONO
CVE-2002-1654HIGH
iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher co
Dec 31, 20027.520NONO
CVE-2001-0327MEDIUM
iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to retrieve sensitive data from memory allocation pools, or cause a denial of service, via a URL-encod
Jul 2, 20015.020NONO
CVE-2002-1315MEDIUM
Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrat
Nov 29, 20026.818NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
53%
41%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown17 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown17 (100.0%)
User Interaction
None0 (0.0%)
Unknown17 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown17 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
5.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Iplanet.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Iplanet — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Iplanet's Products

View all 1 CNAs →

Top CWEs