Nextapp maintains a focused product line centered on the Echo framework and File Explorer utility, where the durable signal concentrates on application-layer input-handling and path-boundary issues such as improper input validation and path-traversal weaknesses. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nextapp over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-5135MEDIUM The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a request containing an external entity declaration in conjunctio | May 2, 2013 | 5.0 | 29 | NO | YES |
CVE-2014-1973MEDIUM Directory traversal vulnerability in the NextApp File Explorer application before 2.1.0.3 for Android allows remote attackers to overwrite or create arbitrary files via a crafted f | Jul 20, 2014 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nextapp.
Media articles that mention a CVE ID that affects a product developed by Nextapp — matched by CVE ID, not by vendor name.