O'Reilly's vulnerability footprint is centered on a narrowly scoped portfolio of website and content-management products that have attracted public exploit tooling. The recurring exposure reflects broad categorization at the NVD level; defenders tracking this vendor should monitor disclosures for the website and professional-edition products specifically and assess exploit-code availability for remediation prioritization. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oreilly over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2000-0622HIGH Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execute arbitrary commands via a URL containing a long "keywords" | Jul 19, 2000 | 10.0 | 41 | NO | YES |
CVE-2001-0626HIGH O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request containing a ":" character. | Aug 22, 2001 | 7.5 | 37 | NO | YES |
CVE-1999-0178HIGH Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string. | Jan 1, 1997 | 7.5 | 34 | NO | YES |
CVE-2001-0743MEDIUM Paging function in O'Reilly WebBoard Pager 4.10 allows remote attackers to cause a denial of service via a message with an escaped ' character followed by JavaScript commands. | Oct 18, 2001 | 5.0 | 29 | NO | YES |
CVE-2000-0623HIGH Buffer overflow in O'Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer header. | Jul 17, 2000 | 10.0 | 26 | NO | NO |
CVE-1999-0177HIGH The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs. | Sep 1, 1997 | 7.5 | 20 | NO | NO |
CVE-2001-0394MEDIUM Remote manager service in Website Pro 3.0.37 allows remote attackers to cause a denial of service via a series of malformed HTTP requests to the /dyn directory. | Aug 22, 2001 | 5.0 | 19 | NO | NO |
CVE-2000-0769HIGH O'Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directly | Oct 20, 2000 | 7.5 | 19 | NO | NO |
CVE-2000-0066MEDIUM WebSite Pro allows remote attackers to determine the real pathname of webdirectories via a malformed URL request. | Jan 13, 2000 | 5.0 | 17 | NO | NO |
CVE-1999-1180MEDIUM O'Reilly WebSite 1.1e and Website Pro 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an argument to (1) args.cmd or (2) args.bat. | Feb 16, 1999 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oreilly.
Media articles that mention a CVE ID that affects a product developed by Oreilly — matched by CVE ID, not by vendor name.