Commerce Server
Vendor:
First CVE: Mar 8, 2002 · Active for 24 years
9
Total CVEs
More Total CVEs than 86% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
22.2%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Commerce Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 8, 2002
24 years ago
Most Recent CVE
Aug 15, 2012
5,091 days ago
CVE Severity & Scoring
Commerce Server9 CVEs
22%
78%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network2 (22.2%)
Unknown7 (77.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (22.2%)
High0 (0.0%)
Unknown7 (77.8%)
User Interaction
None0 (0.0%)
Unknown7 (77.8%)
Required2 (22.2%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (22.2%)
Unknown7 (77.8%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-0158HIGH The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Go | Apr 10, 2012 | 8.8 | 98 | YES | YES |
CVE-2012-1856HIGH The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Serv | Aug 15, 2012 | 8.8 | 92 | YES | NO |
CVE-2007-1201HIGH Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via vectors related to Data | Mar 11, 2008 | 9.3 | 36 | NO | NO |
CVE-2006-1257HIGH The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a | Mar 19, 2006 | 7.5 | 32 | NO | NO |
CVE-2002-0050HIGH Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 allows remote attackers to execute arbitrary code via long authentication data. | Mar 8, 2002 | 7.5 | 30 | NO | NO |
CVE-2002-0622HIGH The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package | Jul 3, 2002 | 7.5 | 27 | NO | NO |
CVE-2002-0623HIGH Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 and 2002 allows remote attackers to execute arbitrary code via long authentication data, aka "New Varia | Jul 3, 2002 | 7.5 | 27 | NO | NO |
CVE-2002-0621MEDIUM Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary co | Jul 3, 2002 | 5.0 | 21 | NO | NO |
CVE-2002-0620MEDIUM Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security conte | Jul 3, 2002 | 5.0 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
2 CVEs
22.2% of CVEs· 98th percentile
Metasploit
1 CVE
11.1% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Commerce Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2009 | 1 | 8.8 | 72.1% | 1 | 0 |
| 2007 | 2 | 8.8 | 86.0% | 2 | 1 |
| 2002 | 4 | 8.0 | 50.4% | 2 | 1 |
| 2000 | 6 | 6.6 | 17.6% | 0 | 0 |