Frontpage

Vendor:

First CVE: Feb 6, 1998 · Active for 28 years

23
Total CVEs
More Total CVEs than 95% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
4.3%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Frontpage over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 6, 1998
28 years ago
Most Recent CVE
Sep 11, 2013
4,699 days ago

CVE Severity & Scoring

Frontpage23 CVEs
All CVEs352,231 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network2 (8.7%)
Unknown21 (91.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (4.3%)
High1 (4.3%)
Unknown21 (91.3%)
User Interaction
None1 (4.3%)
Unknown21 (91.3%)
Required1 (4.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (8.7%)
Unknown21 (91.3%)

Top CVEs

Signals from CVEs in this product scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code v
Feb 3, 20078.884YESNO
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via
Sep 28, 20049.368NOYES
The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting
May 6, 20005.045NOYES
Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitra
Sep 28, 20047.539NONO
Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the "Link View Server-Side Component" vuln
Apr 14, 20007.534NOYES
Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site,
Apr 19, 20007.533NOYES
Microsoft FrontPage 2003 SP3 does not properly parse DTDs, which allows remote attackers to obtain sensitive information via crafted XML data in a FrontPage document, aka "XML Disc
Sep 11, 20134.331NONO
Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause a denial of service via a long
Mar 12, 20015.031NOYES
Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.
Mar 1, 19995.031NOYES
The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, ak
May 11, 20007.529NONO

Exploit Exposure

Signals from CVEs in this product scope (23 CVEs).

CISA KEV
1 CVE
4.3% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
30.4% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (23 CVEs).

Media Mentions

Signals from CVEs in this product scope (23 CVEs).

Top CNAs Publishing CVEs For Frontpage

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9835.018.0%01
9725.016.3%01
200367.832.6%11
200248.736.5%11
200057.627.9%10