Opendap maintains a specialized portfolio of data-access and server products including the Back-End Server (BES), Hyrax framework, and Server3, which serve scientific data distribution and remote access in research and environmental-monitoring contexts. The recorded vulnerabilities cluster around general input-handling and validation concerns characteristic of data-serving infrastructure; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opendap over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2355HIGH The get_url function in DODS_Dispatch.pm for the CGI_server in OPeNDAP 3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. | Apr 30, 2007 | 10.0 | 27 | NO | NO |
CVE-2007-2769HIGH BES before 3.5.0 in OPeNDAP 4 (Hydrax) before 1.2.1 does not properly handle compressed files, which allows remote attackers to upload arbitrary files or execute arbitrary commands | May 21, 2007 | 7.5 | 21 | NO | NO |
CVE-2007-2767HIGH Unspecified vulnerability in BES before 3.5.0 in OPeNDAP 4 (Hydrax) before 1.2.1 allows remote attackers to list filesystem contents and obtain sensitive information via unknown ve | May 21, 2007 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opendap.
Media articles that mention a CVE ID that affects a product developed by Opendap — matched by CVE ID, not by vendor name.