Spey is a modestly represented vendor with a focused product portfolio centered on its primary offering, where the durable signal in its vulnerability disclosures concentrates on application-layer input-handling issues such as improper input validation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spey over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-4847HIGH Unspecified vulnerability in Spey 0.3.3 has unknown impact and attack vectors related to "A number of security holes which could lead to compromise," a different issue than CVE-200 | Dec 31, 2005 | 10.0 | 24 | NO | NO |
CVE-2007-3298HIGH SQL injection vulnerability in Spey before 0.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to MessageProcessor.cc and possibly other | Jun 20, 2007 | 7.5 | 19 | NO | NO |
CVE-2005-4846MEDIUM Format string vulnerability in Logger.cc for Spey 0.3.3 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a | Dec 31, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spey.
Media articles that mention a CVE ID that affects a product developed by Spey — matched by CVE ID, not by vendor name.