Numara develops a compact portfolio of IT service management and asset-tracking products, principally Asset Manager and Footprints, which serve internal IT operations and enterprise infrastructure inventory functions. The recurring vulnerability signal reflects the web application and data-handling context of these tools, clustering around input validation and output-encoding issues such as cross-site scripting and code injection, alongside information-disclosure weaknesses. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Numara over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1173HIGH Multiple buffer overflows in the CentennialIPTransferServer service (XFERWAN.EXE), as used by (1) Centennial Discovery 2006 Feature Pack 1, (2) Numara Asset Manager 8.0, and (3) Sy | May 16, 2007 | 10.0 | 27 | NO | NO |
CVE-2007-2514HIGH Stack-based buffer overflow in XferWan.exe as used in multiple products including (1) Symantec Discovery 6.5, (2) Numara Asset Manager 8.0, and (3) Centennial UK Ltd Discovery 2006 | Jun 6, 2007 | 9.3 | 24 | NO | NO |
CVE-2008-1214HIGH MRcgi/MRProcessIncomingForms.pl in Numara FootPrints 8.1 on Linux allows remote attackers to execute arbitrary code via shell metacharacters in the PROJECTNUM parameter. NOTE: the | Mar 8, 2008 | 7.5 | 21 | NO | NO |
CVE-2007-2950HIGH Centennial Discovery 2006 Feature Pack 1, which is used by (1) Numara Asset Manager 8.0 and (2) Symantec Discovery 6.5, uses insecure permissions on certain directories, which allo | Jul 23, 2007 | 7.2 | 18 | NO | NO |
CVE-2008-1213MEDIUM Cross-site scripting (XSS) vulnerability in Numara FootPrints for Linux 8.1 allows remote attackers to inject arbitrary web script or HTML via the Title form field when setting an | Mar 8, 2008 | 4.3 | 14 | NO | NO |
HP Asset Manager 9.40 and 9.41 before 9.41.11103 P4-rev1 and 9.50 before 9.50.11925 P3 allows local users to obtain sensitive information via unspecified vectors. | Oct 26, 2015 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Numara.
Media articles that mention a CVE ID that affects a product developed by Numara — matched by CVE ID, not by vendor name.