Joseph Allen's vulnerability profile centers on the joe product, with observed weaknesses reflecting improper handling of symbolic links and file-access resolution. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joseph Allen over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0289MEDIUM Joe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow local users to gain privileges of other users by placing a Tro | May 3, 2001 | 4.6 | 21 | NO | YES |
CVE-2000-1178MEDIUM Joe text editor follows symbolic links when creating a rescue copy called DEADJOE during an abnormal exit, which allows local users to overwrite the files of other users whose joe | Jan 9, 2001 | 5.5 | 16 | NO | NO |
Joe text editor 2.8 through 2.9.7 does not remove the group and user setuid bits for backup files, which could allow local users to execute arbitrary setuid and setgid root program | Dec 31, 2002 | 3.6 | 13 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joseph Allen.
Media articles that mention a CVE ID that affects a product developed by Joseph Allen — matched by CVE ID, not by vendor name.