Netsupport develops remote management and educational technology products including Netsupport Manager, DNA Helpdesk, and Netsupport School that facilitate IT administration and classroom control across distributed systems. The vendor's observed vulnerability profile centers on memory-safety, authentication, and input-handling weaknesses—including buffer-boundary violations, improper authentication mechanisms, and SQL injection—characteristic of client-server management platforms with extensive network exposure. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netsupport over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-0404HIGH Stack-based buffer overflow in NetSupport Manager Agent for Linux 11.00, for Solaris 9.50, and for Mac OS X 11.00 allows remote attackers to execute arbitrary code via a long contr | Jan 11, 2011 | 7.5 | 77 | NO | YES |
CVE-2007-5057HIGH NetSupport Manager Client before 10.20.0004 allows remote attackers to bypass the (1) basic and (2) authentication schemes by spoofing the NetSupport Manager. | Sep 24, 2007 | 10.0 | 29 | NO | NO |
CVE-2004-2737HIGH SQL injection vulnerability in problist.asp in NetSupport DNA HelpDesk 1.01 allows remote attackers to execute arbitrary SQL commands via the where parameter. | Dec 31, 2004 | 7.5 | 28 | NO | YES |
CVE-2007-5252HIGH Buffer overflow in NetSupport Manager (NSM) Client 10.00 and 10.20, and NetSupport School Student (NSS) 9.00, allows remote NSM servers to cause a denial of service or possibly exe | Oct 6, 2007 | 10.0 | 26 | NO | NO |
CVE-2004-1861MEDIUM Invision NetSupport School Pro uses a weak encryption algorithm to encrypt passwords, which allows local users to obtain passwords. | Mar 25, 2004 | 4.6 | 23 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netsupport.
Media articles that mention a CVE ID that affects a product developed by Netsupport — matched by CVE ID, not by vendor name.