Project Server

Vendor:

First CVE: Dec 18, 2006 · Active for 19 years

24
Total CVEs
More Total CVEs than 95% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Project Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 18, 2006
19 years ago
Most Recent CVE
Apr 15, 2020
2,291 days ago

CVE Severity & Scoring

Project Server24 CVEs
All CVEs352,294 CVEs
MediumHigh
Attack Vector
Local1 (4.2%)
Network18 (75.0%)
Unknown5 (20.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (75.0%)
High1 (4.2%)
Unknown5 (20.8%)
User Interaction
None10 (41.7%)
Unknown5 (20.8%)
Required9 (37.5%)
Privileges Required
Low15 (62.5%)
High0 (0.0%)
None4 (16.7%)
Unknown5 (20.8%)

Top CVEs

Signals from CVEs in this product scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affe
Jul 11, 20188.148NONO
Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitra
Dec 9, 20099.334NONO
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2016, Office Online Server 2016, Office Web Apps 2010 SP2,Office Web Apps 2013 SP1, Project Server 2013 SP1, Sha
May 12, 20177.833NONO
Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 200
Nov 11, 20159.330NONO
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are saniti
Mar 14, 20188.829NONO
Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are not authorized to read, use the v
Nov 15, 20178.829NONO
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are saniti
Mar 14, 20188.828NONO
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are saniti
Mar 14, 20188.828NONO
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are saniti
Mar 14, 20188.827NONO
Microsoft Windows SharePoint Services 3.0 SP3; SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1; SharePoint Foundation 2010 SP1 and SP2 and 2013 Gold and SP1; Pr
May 14, 20149.027NONO

Exploit Exposure

Signals from CVEs in this product scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (24 CVEs).

Media Mentions

Signals from CVEs in this product scope (24 CVEs).

Top CNAs Publishing CVEs For Project Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2013188.08.3%00
201096.710.1%00
200719.323.5%00
200327.921.9%00