Application Server

Vendor:

First CVE: Mar 15, 2000 · Active for 26 years

199
Total CVEs
More Total CVEs than 99% of tracked products
15.3
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Application Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2000
26 years ago
Most Recent CVE
Apr 21, 2020
2,285 days ago

CVE Severity & Scoring

Application Server199 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local1 (0.5%)
Network3 (1.5%)
Unknown195 (98.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (1.0%)
High2 (1.0%)
Unknown195 (98.0%)
User Interaction
None4 (2.0%)
Unknown195 (98.0%)
Required0 (0.0%)
Privileges Required
Low1 (0.5%)
High0 (0.0%)
None3 (1.5%)
Unknown195 (98.0%)

Top CVEs

Signals from CVEs in this product scope (199 CVEs).

199 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a lar
Aug 12, 20027.581NOYES
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS
Oct 11, 20026.878NOYES
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect hand
Apr 21, 20207.551NONO
Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and Application Server 10.1.2.0.2 has unspecified impact and attack vectors, as ide
Jan 18, 200610.050NOYES
Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requ
Jul 3, 20022.149NONO
Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute
Jul 2, 20017.547NOYES
The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_access restrictions via a reque
May 3, 20057.544NOYES
The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Se
Jul 3, 20025.044NONO
Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'.
Mar 15, 20007.542NOYES
The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.
Aug 12, 20025.040NOYES

Exploit Exposure

Signals from CVEs in this product scope (199 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
17 CVEs
8.5% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (199 CVEs).

Media Mentions

Signals from CVEs in this product scope (199 CVEs).

Top CNAs Publishing CVEs For Application Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
release_1.0.2.0.117.55.3%00
9.2.0.726.53.9%00
9.2.0.635.89.5%01
9.0.4.3497.52.2%00
9.0.4.2259.14.9%00
9.0.4.1237.66.4%01
9.0.4.0126.88.0%01
9.0.4126.87.8%01
9.0.3.1287.36.5%03
9.0.3176.27.4%04
9.0.2.3297.26.3%04
9.0.2.2166.37.7%04
9.0.2.1196.612.9%05
9.0.2.0.1206.37.4%04
9.0.2.0.0206.37.4%04
9.0.2266.214.5%07
9.069.34.6%00
8.3.034.40.4%00
8.2.234.40.4%00
8.1.914.40.4%00