Services
Vendor:
First CVE: Jul 1, 2013 · Active for 13 years
6
Total CVEs
More Total CVEs than 80% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Services over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 1, 2013
13 years ago
Most Recent CVE
Jun 15, 2015
4,057 days ago
CVE Severity & Scoring
Services6 CVEs
67%
33%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown6 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown6 (100.0%)
User Interaction
None0 (0.0%)
Unknown6 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown6 (100.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-9152HIGH The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when creating new user accounts, which makes it easier for remote | Dec 1, 2014 | 7.5 | 20 | NO | NO |
CVE-2014-9151HIGH The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via | Dec 1, 2014 | 7.5 | 19 | NO | NO |
CVE-2013-2158MEDIUM Cross-site request forgery (CSRF) vulnerability in the Services module 6.x-3.x and 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to hijack the authentication of unspeci | Jul 1, 2013 | 6.8 | 18 | NO | NO |
CVE-2015-4393MEDIUM The resource/endpoint for uploading files in the Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote authenticated users with the "Save file information" permission to | Jun 15, 2015 | 6.0 | 17 | NO | NO |
CVE-2015-4394MEDIUM The Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote attackers to bypass the field_access restriction and obtain sensitive private field information via unspecified | Jun 15, 2015 | 5.0 | 15 | NO | NO |
CVE-2014-9153MEDIUM Cross-site scripting (XSS) vulnerability in the Services module 7.x-3.x before 7.x-3.10 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the | Dec 1, 2014 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Services
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.x-3.9 | 3 | 5.9 | 1.4% | 0 | 0 |
| 7.x-3.7 | 2 | 5.5 | 1.6% | 0 | 0 |
| 7.x-3.6 | 2 | 5.5 | 1.6% | 0 | 0 |
| 7.x-3.5 | 2 | 5.5 | 1.6% | 0 | 0 |
| 7.x-3.4 | 2 | 5.5 | 1.6% | 0 | 0 |
| 7.x-3.3 | 3 | 5.9 | 1.3% | 0 | 0 |
| 7.x-3.2 | 3 | 5.9 | 1.3% | 0 | 0 |
| 7.x-3.11 | 2 | 5.5 | 1.6% | 0 | 0 |
| 7.x-3.10 | 2 | 5.5 | 1.6% | 0 | 0 |
| 7.x-3.1 | 3 | 5.9 | 1.3% | 0 | 0 |
| 7.x-3.0 | 3 | 5.9 | 1.3% | 0 | 0 |
| 6.x-3.3 | 1 | 6.8 | 0.7% | 0 | 0 |
| 6.x-3.2 | 1 | 6.8 | 0.7% | 0 | 0 |
| 6.x-3.1 | 1 | 6.8 | 0.7% | 0 | 0 |
| 6.x-3.0 | 1 | 6.8 | 0.7% | 0 | 0 |