Cobalt Raq 2
Vendor:
First CVE: Aug 8, 1999 · Active for 26 years
12
Total CVEs
More Total CVEs than 90% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cobalt Raq 2 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 8, 1999
26 years ago
Most Recent CVE
Aug 12, 2002
8,747 days ago
CVE Severity & Scoring
Cobalt Raq 212 CVEs
17%
33%
50%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown12 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown12 (100.0%)
User Interaction
None0 (0.0%)
Unknown12 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown12 (100.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2000-0442HIGH Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command. | May 24, 2000 | 7.5 | 29 | NO | YES |
CVE-2002-0346HIGH Cross-site scripting vulnerability in Cobalt RAQ 4 allows remote attackers to execute arbitrary script as other Cobalt users via Javascript in a URL to (1) service.cgi or (2) alert | Jun 25, 2002 | 7.5 | 27 | NO | NO |
CVE-2002-0348HIGH service.cgi in Cobalt RAQ 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long service argument. | Jun 25, 2002 | 7.5 | 27 | NO | NO |
CVE-2000-0234MEDIUM The default configuration of Cobalt RaQ2 and RaQ3 as specified in access.conf allows remote attackers to view sensitive contents of a .htaccess file. | Mar 31, 2000 | 5.0 | 25 | NO | YES |
CVE-1999-0722HIGH The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages. | Aug 8, 1999 | 10.0 | 25 | NO | NO |
CVE-2002-0347MEDIUM Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root, via a .. (dot dot) in an HTTP r | Jun 25, 2002 | 5.0 | 21 | NO | NO |
CVE-2000-0431HIGH Cobalt RaQ2 and RaQ3 does not properly set the access permissions and ownership for files that are uploaded via FrontPage, which allows attackers to bypass cgiwrap and modify files | May 22, 2000 | 7.5 | 21 | NO | NO |
MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authentication and overwrite arbitrary files via a symlink attack on a te | Aug 12, 2002 | 3.7 | 20 | NO | YES |
CVE-2000-0117HIGH The siteUserMod.cgi program in Cobalt RaQ2 servers allows any Site Administrator to modify passwords for other users, site administrators, and possibly admin (root). | Jan 30, 2000 | 7.2 | 20 | NO | NO |
CVE-2000-0320MEDIUM Qpopper 2.53 and 3.0 does not properly identify the \n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailb | Apr 21, 2000 | 5.0 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
25.0% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Cobalt Raq 2
Versions
No cataloged versions.