Kodak's vulnerability profile centers on a narrow set of web-facing and document-handling products, particularly the Insite platform and image viewer, where the observed weakness classes cluster around input-handling and code-generation flaws such as cross-site scripting and code injection. Treat this as a compact vendor footprint rather than a broad exposure pattern; live severity, exploitation, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kodak over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2217HIGH Kodak Image Viewer in Microsoft Windows 2000 SP4, and in some cases XP SP2 and Server 2003 SP1 and SP2, allows remote attackers to execute arbitrary code via crafted image files th | Oct 9, 2007 | 9.3 | 56 | NO | YES |
CVE-2011-1427MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Kodak InSite 5.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Language parameter to Pages/logi | Mar 15, 2011 | 4.3 | 25 | NO | YES |
CVE-2017-9085MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Kodak InSite 6.5 to 8.0 allow remote attackers to inject arbitrary web script via the (1) "paramFile" parameter to /Site/Trou | Nov 14, 2017 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kodak.
Media articles that mention a CVE ID that affects a product developed by Kodak — matched by CVE ID, not by vendor name.