Jrun
Vendor:
First CVE: Jun 22, 2000 · Active for 26 years
34
Total CVEs
More Total CVEs than 96% of tracked products
6.8
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Jrun over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 22, 2000
26 years ago
Most Recent CVE
Dec 22, 2005
7,519 days ago
CVE Severity & Scoring
Jrun34 CVEs
68%
29%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown34 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown34 (100.0%)
User Interaction
None0 (0.0%)
Unknown34 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown34 (100.0%)
Top CVEs
Signals from CVEs in this product scope (34 CVEs).
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0665HIGH Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL. | Jul 11, 2002 | 10.0 | 46 | NO | YES |
CVE-2000-1053HIGH Allaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scripting (CSS) attack and directly calling the com.livesoftware. | Dec 11, 2000 | 10.0 | 40 | NO | YES |
CVE-2004-0646HIGH Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with verbose logging enabled, allows | Dec 23, 2004 | 10.0 | 29 | NO | NO |
CVE-2002-0801HIGH Buffer overflow in the ISAPI DLL filter for Macromedia JRun 3.1 allows remote attackers to execute arbitrary code via a direct request to the filter with a long HTTP host header fi | Aug 12, 2002 | 10.0 | 28 | NO | NO |
CVE-2004-1478HIGH JRun 4.0 does not properly generate and handle the JSESSIONID, which allows remote attackers to perform a session fixation attack and hijack a user's HTTP session. | Dec 31, 2004 | 7.5 | 25 | NO | NO |
CVE-2002-0937MEDIUM The Java Server Pages (JSP) engine in JRun allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(nu | Oct 4, 2002 | 5.0 | 25 | NO | YES |
CVE-2000-1050MEDIUM Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request that contains an extra "/" in the beginning of the request ( | Dec 11, 2000 | 5.0 | 25 | NO | YES |
CVE-2004-2182HIGH Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information used by the session server. | Dec 31, 2004 | 7.5 | 24 | NO | NO |
CVE-2005-4472HIGH Stack-based buffer overflow in the Macromedia JRun 4 web server (JWS) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long request th | Dec 22, 2005 | 7.5 | 20 | NO | NO |
CVE-2002-1310HIGH Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia JRun 4.0 and earlier allows remote attackers to execute arbitrary via an HTTP GET | Nov 29, 2002 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (34 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
11.8% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (34 CVEs).
Media Mentions
Signals from CVEs in this product scope (34 CVEs).
Top CNAs Publishing CVEs For Jrun
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.0_build_61650 | 4 | 6.3 | 2.0% | 0 | 0 |
| 4.0 | 15 | 6.1 | 2.9% | 0 | 2 |
| 3.1 | 18 | 6.2 | 3.6% | 0 | 2 |
| 3.0 | 21 | 6.0 | 3.8% | 0 | 3 |
| 2.3.x | 3 | 6.7 | 4.6% | 0 | 1 |
| 2.3.3 | 4 | 5.6 | 2.5% | 0 | 0 |
| 2.3 | 2 | 5.7 | 2.1% | 0 | 0 |