Commerce Server

Vendor:

First CVE: Mar 8, 2002 · Active for 24 years

9
Total CVEs
More Total CVEs than 86% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
22.2%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Commerce Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 8, 2002
24 years ago
Most Recent CVE
Aug 15, 2012
5,091 days ago

CVE Severity & Scoring

Commerce Server9 CVEs
All CVEs352,294 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network2 (22.2%)
Unknown7 (77.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (22.2%)
High0 (0.0%)
Unknown7 (77.8%)
User Interaction
None0 (0.0%)
Unknown7 (77.8%)
Required2 (22.2%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (22.2%)
Unknown7 (77.8%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Go
Apr 10, 20128.898YESYES
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Serv
Aug 15, 20128.892YESNO
Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via vectors related to Data
Mar 11, 20089.336NONO
The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a
Mar 19, 20067.532NONO
Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 allows remote attackers to execute arbitrary code via long authentication data.
Mar 8, 20027.530NONO
The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package
Jul 3, 20027.527NONO
Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 and 2002 allows remote attackers to execute arbitrary code via long authentication data, aka "New Varia
Jul 3, 20027.527NONO
Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary co
Jul 3, 20025.021NONO
Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security conte
Jul 3, 20025.019NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
2 CVEs
22.2% of CVEs· 98th percentile
Metasploit
1 CVE
11.1% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Commerce Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
200918.872.1%10
200728.886.0%21
200248.050.4%21
200066.617.6%00