Marc Ingram operates in the services domain, with a narrow product footprint reflected in the modest volume of associated disclosures. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Marc Ingram over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6910HIGH Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not use timeouts for signed requests, which allows remote attackers to impersonate other users and g | Aug 6, 2009 | 7.5 | 19 | NO | NO |
CVE-2008-6908HIGH Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, uses an insecure hash when signing requests, which allows remote attackers to impersonate other users and | Aug 6, 2009 | 7.5 | 19 | NO | NO |
CVE-2008-6909MEDIUM Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not sign all required data in requests, which has unspecified impact, probably related to man-in-the | Aug 6, 2009 | 6.5 | 17 | NO | NO |
The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "access user profiles" permission to access arbitrary us | Dec 26, 2012 | 2.1 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Marc Ingram.
Media articles that mention a CVE ID that affects a product developed by Marc Ingram — matched by CVE ID, not by vendor name.