Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sawmill

First CVE: Jun 26, 2000Active for: 26 yearsTotal CVEs: 9

Sawmill is a focused log-analysis and reporting platform whose vulnerability profile, despite a narrow product scope, has drawn attention in the vulnerability landscape due to its role in processing and exposing operational data. The vendor's disclosures skew toward serious outcomes, reaching critical severity in a meaningful share of cases, and frequently acquire public exploit code; the recurring weakness classes center on input-validation and cross-site scripting issues alongside improper handling of sensitive information exposure, typical of web-facing analytics applications. Defenders should prioritize visibility into internet-exposed instances and treat updates as moderately urgent; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sawmill over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 26, 2000
26 years ago
Most Recent CVE
Mar 15, 2017
3,418 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-5496CRITICAL
Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash.
Mar 15, 20179.836NOYES
CVE-2000-0589HIGH
SawMill 5.0.21 uses weak encryption to store passwords, which allows attackers to easily decrypt the password and modify the SawMill configuration.
Jun 26, 20007.532NOYES
CVE-2000-0588MEDIUM
SawMill 5.0.21 CGI program allows remote attackers to read the first line of arbitrary files by listing the file in the rfcf parameter, whose contents SawMill attempts to parse as
Jun 26, 20005.025NOYES
CVE-2002-0265MEDIUM
Sawmill for Solaris 6.2.14 and earlier creates the AdminPassword file with world-writable permissions, which allows local users to gain privileges by modifying the file.
May 29, 20024.621NOYES
CVE-2005-1900HIGH
Sawmill before 7.1.6 allows remote attackers to bypass authentication and (1) gain administrative privileges or (2) add a license.
Jun 9, 20057.520NONO
CVE-2013-4947HIGH
Unspecified vulnerability in the update and build database page in Sawmill before 8.6.3 allows remote attackers to have unknown impact and attack vectors.
Jul 29, 20137.519NONO
CVE-2010-1079MEDIUM
Cross-site scripting (XSS) vulnerability in Sawmill before 7.2.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Mar 23, 20104.316NONO
CVE-2005-2950MEDIUM
Cross-site scripting (XSS) vulnerability in Sawmill 7.0.0 through 7.1.13 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP GET request.
Sep 16, 20054.314NONO
CVE-2005-1901MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Sawmill before 7.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) the username in the Add User windo
Jun 9, 20054.314NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
56%
33%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network1 (11.1%)
Unknown8 (88.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (11.1%)
High0 (0.0%)
Unknown8 (88.9%)
User Interaction
None1 (11.1%)
Unknown8 (88.9%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (11.1%)
Unknown8 (88.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
44.4% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sawmill.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sawmill — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sawmill's Products

View all 1 CNAs →

Top CWEs