Marcus Schafer's vulnerability profile centers on the Kiwi product, a web-based utility that has attracted a recurring pattern of input-handling and validation issues spanning cross-site scripting and improper input neutralization. The exposure is modest in volume but reflects the attack surface inherent to web-facing applications where user input must be carefully sanitized. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Marcus Schafer over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-2225HIGH Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to have an unknown impact via a crafted directory pathname that is insert | Aug 23, 2011 | 9.3 | 28 | NO | NO |
CVE-2011-2649HIGH Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to execute arbitrary commands via shell metacharacters in an unspecified FileUtils function call. | Aug 23, 2011 | 7.5 | 23 | NO | NO |
CVE-2011-2648HIGH Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a filter in a modified file. | Aug 23, 2011 | 7.5 | 23 | NO | NO |
CVE-2011-2647HIGH Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted archive name in the list o | Aug 23, 2011 | 7.5 | 23 | NO | NO |
CVE-2011-2646HIGH Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename in the list of te | Aug 23, 2011 | 7.5 | 23 | NO | NO |
CVE-2011-2645HIGH Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename for a custom RPM. | Aug 23, 2011 | 7.5 | 23 | NO | NO |
CVE-2011-2651HIGH Unspecified vulnerability in the file browser in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filena | Aug 23, 2011 | 7.5 | 22 | NO | NO |
CVE-2011-2652MEDIUM Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafte | Aug 23, 2011 | 4.3 | 16 | NO | NO |
CVE-2011-2650MEDIUM Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafte | Aug 23, 2011 | 4.3 | 16 | NO | NO |
CVE-2011-2644MEDIUM Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecif | Aug 23, 2011 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Marcus Schafer.
Media articles that mention a CVE ID that affects a product developed by Marcus Schafer — matched by CVE ID, not by vendor name.