Pi3 maintains a narrowly scoped product line centered on its web application, Pi3Web, which serves a specialized deployment context. The vendor's disclosed vulnerabilities are characterized by a strong tendency toward public exploit availability, making timely patching a priority despite the focused product footprint. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pi3 over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0142HIGH CGI handler in John Roy Pi3Web for Windows 2.0 beta 1 and 2 allows remote attackers to cause a denial of service (crash) via a series of requests whose physical path is exactly 260 | Mar 25, 2002 | 7.5 | 29 | NO | YES |
CVE-2003-0276MEDIUM Buffer overflow in Pi3Web 2.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GET request with a large number of / characte | Jun 16, 2003 | 5.0 | 27 | NO | YES |
CVE-2001-0302MEDIUM Buffer overflow in tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL. | May 3, 2001 | 5.0 | 25 | NO | YES |
CVE-2003-1032MEDIUM Pi3Web web server 2.0.2 Beta 1, when the Directory Index is configured to use the "Name" column and sort using the column title as a hyperlink, allows remote attackers to cause a d | Feb 17, 2004 | 5.0 | 23 | NO | YES |
CVE-2002-0433MEDIUM Pi3Web 2.0.0 allows remote attackers to view restricted files via an HTTP request containing a "*" (wildcard or asterisk) character. | Jul 26, 2002 | 5.0 | 15 | NO | NO |
CVE-2001-0303MEDIUM tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to determine the physical path of the server via a URL that requests a non-existent file. | May 3, 2001 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pi3.
Media articles that mention a CVE ID that affects a product developed by Pi3 — matched by CVE ID, not by vendor name.